1. Reporting a Security Vulnerability
Security vulnerabilities may be submitted without creating an account, logging into a customer portal, owning a Hanshow product, or completing any registration process.
Reports may be submitted through either of the following channels:
Security Email
security@hanshow.com
Online Submission
Submit a vulnerability report through the Hanshow Contact Us form.
Submit a Vulnerability ReportAnonymous reports are accepted. However, providing valid contact information is recommended so that Hanshow can:
- Confirm receipt of the report;
- Request additional technical information;
- Provide investigation and remediation updates;
- Coordinate vulnerability disclosure;
- Share resolution feedback.
The Hanshow Security Team reviews submitted reports and coordinates the vulnerability handling process.
2. Scope of This Policy
This Vulnerability Disclosure Policy applies to supported products, services, software components, and associated systems developed, maintained, operated, or officially supported by Hanshow.
Covered Assets
Websites and Applications
Hanshow corporate websites, web applications, and customer-facing platforms.
Cloud and Backend Systems
Cloud platforms, backend services, and related operational infrastructure.
Product Software
Firmware, embedded software, mobile applications, and product-related software.
APIs and Interfaces
APIs, software interfaces, product update services, and associated digital components.
Supporting Infrastructure
Infrastructure associated with the operation of supported Hanshow products and services.
Third-Party Components
Third-party or open-source components where an issue directly affects a supported Hanshow product or service.
Out of Scope
- Denial-of-service or distributed denial-of-service testing;
- Social engineering, phishing, or impersonation;
- Physical security testing;
- Spam or unsolicited bulk communications;
- Automated scanning that may affect service availability;
- Testing third-party systems outside Hanshow’s control;
- Testing unsupported or end-of-life products, unless otherwise agreed;
- Accessing, modifying, deleting, or extracting customer or personal data beyond what is strictly necessary to demonstrate a vulnerability.
Reporters who are unsure whether an asset or testing activity is within scope should contact the Hanshow Security Team before continuing.
3. Responsible Security Research
Security researchers are expected to conduct testing responsibly and minimize potential impact on Hanshow systems, customers, and users.
- Conduct testing in good faith;
- Avoid disrupting services or normal business operations;
- Avoid accessing, changing, deleting, or downloading customer data;
- Only perform testing necessary to demonstrate the existence of a vulnerability;
- Stop testing once sufficient evidence has been collected;
- Protect vulnerability information from unauthorized disclosure;
- Provide sufficient technical information to support validation and remediation;
- Allow Hanshow a reasonable opportunity to investigate and address the issue before public disclosure.
4. Vulnerability Report Requirements
To support efficient validation and investigation, vulnerability reports should include as much of the following information as reasonably available.
Basic Information
- Reporter name or organization, if not anonymous;
- Contact information for follow-up communication;
- Affected product, service, system, URL, API, or component;
- Affected model, firmware, software, or service version;
- A clear description of the suspected vulnerability.
Technical Information
- Vulnerability category;
- Steps required to reproduce the issue;
- Proof-of-concept information, where appropriate;
- Screenshots, logs, request and response samples, or supporting evidence;
- Testing environment and configuration;
- Required attack conditions or prerequisites;
- Whether the issue can be exploited remotely, locally, or physically.
Impact Information
- Potential impact on confidentiality, integrity, availability, privacy, or safety;
- Potential attack scenario;
- Known or suspected exploitation;
- Whether the vulnerability or proof of concept has been publicly disclosed;
- Suggested remediation or mitigation, where available.
A report containing sufficient technical information can generally be evaluated more efficiently.
5. Vulnerability Categories
Hanshow welcomes reports concerning vulnerabilities that may affect the confidentiality, integrity, or availability of supported products, services, software, and related systems.
Examples of vulnerability categories include, but are not limited to:
Access Control
- Authentication bypass;
- Authorization weaknesses;
- Privilege escalation;
- Insecure access-control implementation;
- Session-management vulnerabilities.
Application and API Security
- Injection vulnerabilities;
- Cross-site scripting;
- Cross-site request forgery;
- API authentication or authorization issues;
- Remote code execution;
- Insecure file handling;
- Server-side request forgery.
Product and System Security
- Sensitive information exposure;
- Insecure data storage or transmission;
- Cryptographic weaknesses;
- Security misconfiguration;
- Firmware or embedded-software vulnerabilities;
- Vulnerable third-party or open-source components;
- Software update or integrity-verification weaknesses.
6. Vulnerability Severity Assessment
Hanshow evaluates reported vulnerabilities using the Common Vulnerability Scoring System, CVSS v4.0, where applicable.
The assessment considers factors including:
- Exploitability;
- Attack complexity and required privileges;
- User interaction requirements;
- Exposure of the affected asset;
- Impact on confidentiality, integrity, and availability;
- Potential customer, operational, privacy, or safety impact;
- Active exploitation or availability of public exploit code;
- Availability of compensating controls or mitigations.
Hanshow may adjust remediation priority based on product context, affected deployment environments, exploitation status, customer impact, and other relevant business or regulatory risks.
| Severity | CVSS v4.0 Score | Description | Target Remediation Time |
|---|---|---|---|
| Critical | 9.0–10.0 | Vulnerabilities that may result in severe security impact, such as remote code execution, major unauthorized system access, significant data exposure, widespread compromise, or active exploitation. | Within 30 days |
| High | 7.0–8.9 | Vulnerabilities that may allow significant unauthorized access, privilege escalation, sensitive information exposure, or substantial compromise under realistic attack conditions. | Within 60 days |
| Medium | 4.0–6.9 | Vulnerabilities with moderate impact or vulnerabilities that require specific attack conditions, access, or user interaction. | Within 90 days |
| Low | 0.1–3.9 | Security weaknesses with limited practical impact, low exploitability, or a narrow affected scope. | Within 180 days |
If permanent remediation cannot be completed within the target timeline, Hanshow may implement temporary mitigations or compensating controls. Any revised remediation plan will be documented and tracked internally.
7. Vulnerability Response Commitment
Hanshow is committed to managing vulnerability reports in a timely, transparent, and responsible manner throughout the vulnerability handling lifecycle.
Initial Acknowledgement
Hanshow normally acknowledges receipt of a vulnerability report within five business days, provided that valid contact information is available.
Status Updates
- Critical vulnerabilities: at least every 14 days.
- High vulnerabilities: at least every 30 days.
- Medium and Low vulnerabilities: when significant progress or a material status change occurs.
Communication
Communication may be conducted through the original reporting channel, security email, or another mutually agreed secure communication method. The Hanshow Security Team is responsible for maintaining communication with the reporter.
Acknowledgement May Include
- Confirmation that the report has been received.
- A tracking reference, where applicable.
- Initial review status.
- A request for additional technical information if required.
8. Vulnerability Status
Throughout the vulnerability handling lifecycle, reports may be assigned one of the following statuses.
Received
The vulnerability report has been received and recorded by Hanshow.
Under Review
The Hanshow Security Team is validating the reported issue, confirming scope, and determining whether sufficient technical information has been provided.
Confirmed
The vulnerability has been reproduced, validated, assigned a severity level, and entered into the remediation process.
In Remediation
Engineering teams are implementing and validating a permanent fix or an appropriate mitigation.
Resolved
A remediation or mitigation has been implemented, verified, and prepared for release or deployment.
Closed
The vulnerability handling process has been completed. Reports may also be closed if they are duplicates, out of scope, not reproducible, or determined not to represent a security vulnerability.
9. Vulnerability Monitoring and Tracking
The Hanshow Security Team serves as the Vulnerability Monitoring and Tracking Coordinator and is responsible for coordinating the complete vulnerability lifecycle from initial report through remediation, disclosure, and closure.
Responsibilities
- Monitor designated vulnerability reporting channels.
- Receive, register, and track reported vulnerabilities.
- Coordinate validation and severity assessment.
- Maintain vulnerability records and tracking status.
- Coordinate communication between reporters and internal teams.
- Coordinate engineering, testing, operations, legal, compliance, and customer support activities.
- Track remediation progress and target timelines.
- Coordinate temporary mitigations and permanent fixes.
- Coordinate Security Advisory publication where appropriate.
- Maintain handling records and escalate significant security issues when required.
10. Vulnerability Handling Process
Hanshow follows a structured vulnerability handling process to ensure reported issues are consistently evaluated, remediated, verified, and communicated.
Intake and Registration
Vulnerability reports are received through official reporting channels, registered, assigned a tracking reference where applicable, and prepared for review.
Initial Review and Validation
The Hanshow Security Team confirms scope, reviews submitted evidence, attempts to reproduce the reported issue, and requests additional information if necessary.
Severity and Impact Assessment
Vulnerabilities are evaluated using CVSS v4.0 where applicable together with exploitability, customer impact, affected products, and deployment context.
Solution Evaluation
Appropriate remediation strategies are evaluated, including software updates, firmware changes, configuration updates, temporary mitigations, and operational controls.
Remediation Development
Engineering teams implement and validate the selected remediation. Critical vulnerabilities may follow an expedited handling process.
Verification and Testing
Remediation is verified to ensure the vulnerability has been resolved without introducing new security or functional issues.
Release and Deployment
Approved patches, firmware updates, software releases, configuration changes, or mitigations are deployed through appropriate release channels.
Disclosure and Notification
Where appropriate, Hanshow coordinates customer notification and may publish a Security Advisory after remediation or suitable mitigation measures become available.
Monitoring and Closure
Hanshow confirms remediation effectiveness, records lessons learned, updates tracking records, and formally closes the vulnerability handling process.
11. Coordinated Vulnerability Disclosure
Hanshow supports Coordinated Vulnerability Disclosure (CVD) to reduce the risk of exploitation before appropriate remediation or mitigation becomes available.
Disclosure Timing Considerations
Public disclosure timing is evaluated based on multiple factors, including:
- Severity of the vulnerability;
- Evidence of active exploitation;
- Availability of public proof-of-concept or exploit code;
- Customer and operational impact;
- Availability of mitigation or remediation;
- Deployment readiness;
- Coordination with affected suppliers or third parties;
- Applicable legal or regulatory requirements.
Public Disclosure
Vulnerability information is normally disclosed only after appropriate remediation or mitigation has become available and affected customers have had a reasonable opportunity to take action.
Coordinated Communication
Hanshow may coordinate disclosure activities with researchers, customers, suppliers, industry partners, and relevant authorities where appropriate.
12. Confidentiality Before Resolution
Until authorized public disclosure occurs, vulnerability-related information should be treated as confidential by both Hanshow and the reporter.
Confidential Information May Include
- Unpublished technical details;
- Proof-of-concept code;
- Exploitation techniques;
- Affected customer information;
- Internal investigation results;
- Remediation progress;
- Unreleased patches, firmware, or software updates;
- Security testing and validation records.
Reporter Responsibilities
Reporters are expected not to publicly disclose vulnerability information before coordinated disclosure has been agreed or appropriate remediation has become available.
Hanshow Responsibilities
Hanshow limits access to vulnerability information to personnel who require it for investigation, remediation, validation, communication, compliance, or disclosure activities.
13. Researcher Recognition
Hanshow appreciates security researchers who responsibly report vulnerabilities and contribute to improving the security of Hanshow products and services.
Recognition May Include
- Acknowledgement in a published Security Advisory.
- Public recognition on Hanshow security communications.
- Certificate or letter of appreciation.
- Other non-monetary recognition where appropriate.
Reporters may choose to remain anonymous. Hanshow will not publicly disclose reporter information without permission. Hanshow does not currently operate a public monetary bug bounty program.
14. Safe Harbor
Hanshow supports good-faith security research conducted in accordance with this policy. Hanshow does not intend to pursue legal action against researchers who comply with the following principles.
- Act in good faith.
- Comply with this Vulnerability Disclosure Policy.
- Avoid service disruption or damage.
- Avoid privacy violations.
- Do not access, modify, delete, or disclose unnecessary data.
- Do not exploit vulnerabilities beyond what is necessary to demonstrate their existence.
- Report vulnerabilities responsibly.
- Cooperate with reasonable requests related to investigation and disclosure.
This Safe Harbor statement does not authorize activities that violate applicable laws or the rights of third parties.
15. Vulnerability Escalation
Reporters who believe a vulnerability has not been handled appropriately may request escalation.
Step 1 – Follow-up
Contact the Hanshow Security Team using the original reporting channel and include the relevant tracking information.
Step 2 – Security Management Review
If no response is received within ten business days following the follow-up request, the reporter may request review by Hanshow Security Management.
Step 3 – Senior Review
Critical unresolved vulnerabilities, significant customer risks, active exploitation, or material regulatory issues may be escalated to senior security, technology, legal, compliance, or executive leadership.
16. Security Advisory Publication
Hanshow may publish a Security Advisory when a vulnerability requires public communication, customer awareness, or remediation guidance.
A Security Advisory may include:
- Advisory ID
- Publication date
- Last revision date
- Vulnerability title
- Severity rating
- CVSS v4.0 score and vector (where applicable)
- CVE identifier (if assigned)
- Affected products and versions
- Vulnerability description
- Security impact
- Remediation guidance
- Available mitigations or workarounds
- Revision history
- Researcher acknowledgement where permission has been provided.
Technical details that could unnecessarily facilitate exploitation may be withheld until suitable remediation is available and affected customers have had a reasonable opportunity to apply updates.
View Security Advisories17. Privacy of Submitted Information
Information submitted as part of a vulnerability report will be handled responsibly and used solely for activities related to vulnerability management, remediation, security improvement, and compliance obligations.
Submitted Information May Be Used For
- Vulnerability validation and investigation.
- Communication with the reporter.
- Remediation and mitigation activities.
- Product and service security improvements.
- Compliance, audit, and legal obligations.
- Security records and vulnerability tracking.
Reporter information will not be publicly disclosed without permission unless required by applicable law. Vulnerability information is shared only with personnel who require access for investigation, remediation, validation, communication, compliance, or coordinated disclosure.
18. Contact the Hanshow Security Team
If you believe you have discovered a security vulnerability in a Hanshow product, service, or system, please submit your report through one of the following official channels.
Security Email
security@hanshow.com
Help Us Improve Security
Hanshow values responsible vulnerability disclosure and appreciates the efforts of the global security community in helping us protect our products, services, customers, and partners.
Submit a Vulnerability Report