Vulnerability Disclosure
Foreword
Shenzhen Zolon Technology Co., Ltd. ("ZOLON" or "we") is committed to enhancing the security of our products and services and fully supports the secure operation of customers' networks and services. We encourage security researchers, industry organizations, customers and suppliers to report suspected vulnerabilities related to ZOLON's publicly accessible assets. ZOLON has established a process for handling reported suspected vulnerabilities.
Security researchers should put the interests of users first and respect user privacy. ZOLON encourages relevant parties to discover and report vulnerabilities in a lawful manner, and commits to cooperating with security researchers to understand, confirm and properly resolve vulnerabilities. Before submitting vulnerability information to ZOLON, you must not disclose the vulnerability information to anyone other than ZOLON. Any public disclosure without ZOLON's written consent will violate the terms and conditions of this program.
ZOLON urges reporters to follow a responsible disclosure policy — that is, to notify us privately before fully disclosing any security vulnerability, so that we can resolve the vulnerability and minimize the overall risk to users. Throughout the process, ZOLON will strictly control the distribution of information. ZOLON will require reporters to keep the vulnerability confidential until ZOLON completes the fix.
Handling Process
1. Identify
To report a potential vulnerability affecting ZOLON products or solutions, please contact ZOLON using the method described in the Contact Us section below.
In particular, please include [VULNERABILITY] in the subject line of your email when reporting a potential vulnerability. If your submission is incomplete, incorrect, duplicate or false, ZOLON will not process it.
Required information (please use the template for reporting suspected vulnerabilities):
- Channel through which the device was acquired;
- Affected product/service, including model name, serial number (SN), hardware version (PN), operating system or software version;
- Vulnerability summary, including problem description and vulnerability type;
- Impact (arbitrary code execution, information disclosure, etc.) and severity assessment;
- Technical details and steps to reproduce the issue;
- Proof of concept (PoC) or other substantive evidence;
- Description of the attack scenario, including preconditions, triggers, and whether interaction with the victim is required;
- Mitigation recommendations.
ZOLON usually responds to complete and correct reports within 5 business days. If you do not receive a reply, please check that our emails have not been marked as spam.
2. Verify
ZOLON investigates and reproduces the potential issue.
The verification process is typically completed within 10 business days. Given the complexity of the potential issue, this period may be extended by up to one month when necessary.
3. Fix
ZOLON collaborates with the relevant security and development teams on internal vulnerability handling, and will maintain a vulnerability mitigation and recovery plan for affected products or solutions.
The duration of this phase varies depending on risk level, impact and difficulty.
4. Release
Where applicable, patches or fixes will be provided through regular release channels.
Contact Us
To contact ZOLON about any security issue related to our products or solutions, please send an email to VulnerabilityDisclosure@szzolon.com
Please note that only English or Chinese emails are accepted.
Please encrypt your report using our public PGP key (Key ID: 21B0 226B; Fingerprint: D0E2 92E3 C558 C441 C31A E973 EFDB 5A1C 21B0 226B).
Disclaimer
Notwithstanding the above terms and conditions, ZOLON reserves the final right of interpretation with respect to the identification and evaluation of vulnerability reports (including but not limited to vulnerability validity, report eligibility and vulnerability severity). ZOLON also reserves the right to pursue legal liability in accordance with applicable laws and regulations for illegal testing and disclosure.