Ecovacs Coordinated Vulnerability Disclosure (CVD) Policy
Version: V1.0Latest Revision Date: August 10, 2026
- Introduction
This policy describes our commitment to product security and how we work with the security community through Coordinated Vulnerability Disclosure (CVD).
What is Coordinated Vulnerability Disclosure (CVD)?
Coordinated Vulnerability Disclosure is a process for responsibly handling security vulnerabilities through coordination among relevant stakeholders. The core principle of CVD is to avoid publicly disclosing detailed information about a vulnerability until a remediation is available and users have had a reasonable opportunity to apply the remediation. This approach helps maximize user protection while fostering trust and cooperation between security researchers and product manufacturers.
- Scope
- Robot hardware and firmware
- Mobile applications (APPs)
- Cloud platforms and API services
- OTA update platforms
- Third-party components and open-source software
- Theoretical vulnerabilities for which no actual exploitability or demonstrable security impact has been established;
- Simple disclosure of non-sensitive information, such as version information;
- Vulnerabilities affecting products that had reached End of Life (EOL) more than 12 months before the date of the report;
- Vulnerabilities identified solely through automated scanning tools and not independently validated;
- UI/UX defects or spelling errors that have no security impact;
- Social engineering attacks and physical security testing.
- Vulnerability Reporting Channels
| Channel | Address | Description |
| Security Email (Preferred) | product-security@ecovacs.com | Supports PGP-encrypted communication. The public key can be obtained from the address provided in this document. |
| Online Submission Form | https://security.ecovacs.cn/en/submit-vulnerability | Supports anonymous vulnerability reporting. |
All electronic reporting channels use HTTPS/TLS encryption for data transmission. The security email supports PGP-encrypted communication.
Accessibility: On the Product Security Center website, select “Screen Reader” from the accessibility menu to enable or disable screen reader assistance. Other accessibility options, such as contrast adjustment and link highlighting, are also available as needed.
- Safe Harbor
- Treating their research activities as authorized;
- Not initiating legal action or referring the matter to law enforcement solely because of their good-faith security research;
- Cooperating in good faith to understand and remediate the reported vulnerability as efficiently as reasonably possible.
- Interact only with systems that the researcher owns or is explicitly authorized to test;
- Avoid accessing or compromising user privacy, damaging data, or degrading the availability or performance of products or services;
- Access only the minimum amount of data necessary to demonstrate the vulnerability and do not retain, disclose, or misuse such data;
- Provide us with a reasonable opportunity to remediate the vulnerability before public disclosure;
- Do not use the research results for malicious purposes.
- Report Content Requirements
| Description | Required | |
| Affected Product | Product name, model, and firmware/APP/cloud version | Yes |
| Vulnerability Description | Description of the issue, triggering conditions, and vulnerability type | Yes |
| Reproduction Steps | Detailed step-by-step instructions for reproducing the vulnerability | Yes |
| Impact Assessment | Potential security impact if the vulnerability is exploited | Yes |
| Proof of Concept (PoC) | Technical demonstration sufficient to demonstrate the existence of the vulnerability (non-weaponized) | Recommended |
| Discovery Information | Date and method of discovery | Recommended |
| Contact Information | Name/alias and email address (may be omitted for anonymous reports) | Recommended |
- Our Commitments to Reporters
| Commitment | Target Timeline | |
| Acknowledgment | Send an acknowledgment and assign a tracking number | Within 3 calendar days |
| Initial Assessment | Complete vulnerability validation and classification | Within 14 calendar days |
| Progress Updates | Provide the reporter with updates when there is material progress | As progress is made |
| Remediation Completed | Notify the reporter when remediation has been completed and, where appropriate, invite verification | After remediation is completed |
| Coordinated Disclosure | Coordinate with the reporter regarding the timing and content of public disclosure | After the patch is released |
- Critical/High-severity vulnerabilities: Target remediation within 90 calendar days
- Low-severity vulnerabilities: Target remediation within 180 calendar days
- Coordinated Disclosure Principles
- Technical details of the vulnerability;
- Proof-of-concept code and exploitation methods;
- Affected product and version ranges;
- Technical details of the remediation;
- Unpublished security advisory drafts.
We will not publicly disclose detailed information about a reported vulnerability while remediation is in progress. Any public disclosure should, where reasonably practicable, be coordinated between the reporter and us.
Where appropriate, we may agree on a non-disclosure period during which detailed vulnerability information will not be publicly disclosed. The duration of the non-disclosure period may be adjusted on a case-by-case basis by mutual agreement, including where coordination with a coordinating party, third-party component provider, or other supplier is required.
- Public Disclosure
8.1 Security Advisory Content
Following the release of a security update, we will publish a security advisory on our official Security Announcement page. The advisory will include, at a minimum:- Vulnerability description;
- Vulnerability identifier (CVE ID or vendor-assigned identifier);
- Identification information for affected products;
- Potential security impact of the vulnerability;
- Vulnerability severity, including the CVSS score where applicable;
- Remediation information;
- Publication date and update date.
8.2 Publication Channels
Security vulnerability information may be published through the following channels:- Official Security Announcement page:
- https://security.ecovacs.cn/en/security-announcement
- Machine-readable format: CSAF 2.0 JSON:
- https://security.ecovacs.cn/cn/advisories.json
- CVE records and the European Union Vulnerability Database (EUVD), where applicable;
- Product update and notification channels, where applicable.
- Acknowledgments
The reporter may choose to:
- Use their real name;
- Use a pseudonym;
- Remain anonymous.
- Policy Updates
Major changes are recorded below:
| Date | Changes | |
| V1.0 | August 10, 2026 | Initial release |
- Contact Information
| Purpose | Contact |
| Vulnerability Reports | product-security@ecovacs.com |
| Policy Feedback | product-security@ecovacs.com (Subject: “Policy Feedback”) |
| PGP Public Key | https://security.ecovacs.cn/public-key.asc |
| Security Advisory Page | https://security.ecovacs.cn/en/security-announcement |
| security.txt | https://www.ecovacs.com/.well-known/security.txt |
