Vulnerability Handling · Vulnerability Management Process
Vulnerability Management Process ›Vulnerability Handling
< Return to Vulnerability Management Process

Vulnerability Disclosure Policy

Our vulnerability disclosure policy for connected products

 

We are committed to providing the highest quality products and services, and to ensuring the security of our customers' information when using our products. Cyber threats are increasingly an obstacle to achieving these goals; we have a professional security incident response team that coordinates and addresses security vulnerabilities. If you believe you have found a security vulnerability in one of our products, please follow our disclosure process to contact iotsecurity@cn.gree.com
We will work with all relevant parties (such as R & D team, legal department, etc.) to deal with the loopholes in the missed report in a timely manner. It is recommended that you contact us through the prescribed channels and provide the required relevant information; we will reply within 30 working days after receiving the vulnerability report. We may regularly update the progress of the problem, and your contribution will be reflected on our thank you page. We will not bring any action against a person who reports a vulnerability to us, provided that the person does not publicly disclose the details of the vulnerability until we have confirmed that the vulnerability has been completely fixed.