Select your country or region
If you encounter or discover any suspected vulnerabilities in MAXHUB products, please inform MAXHUB promptly. For PSIRT, please refer to the vulnerability reporting channels and security mechanisms to submit suspected vulnerabilities.
You can submit suspected vulnerabilities related to MAXHUB products via email using the template provided . PSIRT will verify any suspected vulnerabilities reported by security researchers, industry organizations, customers, and suppliers as soon as possible.
| Channel | Note |
|---|---|
| Email address: security@maxhub.com | MAXHUB within 24 hours . PSIRT confirmed the issue via email and will keep you informed of the progress of the problem as it unfolds. |
| Telephone: +86-020-82086168 | 9:00-18:00 (GMT+8) |
Encrypt any messages sent to security@maxhub.com using PGP (Pretty Good Privacy) . Our PGP public key (key ID 0x50A34966; PGP fingerprint: 5930 0A75 BD8C 54CA 6471 B25A 998D D4C6 50A3 4966 ) can be obtained by clicking here .
Throughout the vulnerability handling process, MAXHUB PSIRT strictly controls the scope of vulnerability information, disseminating it only among personnel involved in handling vulnerabilities; it also requests that the person reporting the vulnerability keep the information confidential until our clients have obtained a complete solution.
MAXHUB PSIRT focuses on receiving all vulnerabilities related to MAXHUB products. For issues with MAXHUB products (such as product configuration, patch acquisition, and live vulnerability remediation support), you can directly contact MAXHUB after-sales support for relevant technical support. MAXHUB will handle vulnerabilities identified by after-sales support during the technical support process according to its internal procedures .
We commit to providing feedback and tracking the progress of your vulnerability reports according to the following steps.
| Node | Commitment Time Limit |
|---|---|
| Confirm receipt of report and assign tracking number | 3 business days |
| Preliminary verification results feedback (valid/invalid/requires supplementation) | 10 business days |
| Processing progress update | At least once every 30 days until closed. |
| Fixes, releases, and announcements | 10 business days after the vulnerability is patched |
1. The default coordination and disclosure period is 90 days from the date of verification and confirmation;
2. Please do not disclose vulnerability details before a fix is available and an announcement is released . We also promise to fix the vulnerability promptly and explain it in the announcement ;
3. After the patch is released, we will publish the patched vulnerability information in accordance with the "Security Bulletin" ;
With your consent, we will acknowledge you in the security bulletin or on the acknowledgments page.
To protect user privacy, data security, and service stability, please ensure that reporters adhere to the following boundaries when verifying vulnerabilities:
1. Only test to the minimum necessary extent to verify vulnerabilities, and avoid unnecessary in-depth probing;
2. Do not damage, tamper with, delete, download, or disclose any sensitive or business data that does not belong to you;
3. Do not engage in destructive behaviors such as DoS/DDoS attacks, social engineering, physical attacks, malicious persistence, ransomware, or lateral movement;
4. Do not conduct any tests that may affect the stability of the production environment and service availability;
5. Do not disclose sensitive details to third parties before the vulnerability has been patched .
This policy is maintained by the Information Security Department and reviewed at least once a year.
This site uses cookies to personalise your experience and analyse site traffic. By clicking ACCEPT or continuing to browse the site, you are agreeing to our use of cookies. See our Cookies and Privacy Policy here
{$ text $}