Security Response Center

Saswell is committed to ensuring the secure and stable operation of its products and customer systems. We welcome and appreciate security researchers, customers, and partners who report potential security vulnerabilities to us in a responsible manner.
Cyber Resilience Act Scope

How to Report a Vulnerability

Please send your vulnerability report to the dedicated email address:

psirt@saswell.com
What to Include in Your Report?
To help us accurately and efficiently assess and handle your submission, please include as much of the following information as possible:
Item Description
Contact Information Name and email (optional but recommended for follow‑up)
Affected Product(s) Product name, model, firmware/software version
Vulnerability Description Detailed description of the vulnerability, including the discovery date
Reproduction Steps Clear, reproducible steps to demonstrate the vulnerability
Impact Analysis What can an attacker do? (e.g., privilege escalation, data breach, service disruption)
Supporting Evidence Screenshots, logs, proof‑of‑concept code, test scripts, etc.
Public Disclosure Status Whether this vulnerability has already been publicly disclosed by you or others

Our Commitment

Upon receiving your report, we will follow the response process below:
Intake
Assessment
Remediation
Distribution
Reporting
Vulnerability severity is rated using the CVSS v3.1/v4.0 international standard:
Risk Level CVSS Score Range Definition and Impact Characteristics
Critical 9.0 – 10.0 Remotely exploitable without authentication; can lead to device compromise, arbitrary code execution (RCE), or severe exfiltration of sensitive data.
High 7.0 – 8.9 Low attack complexity; can result in the loss of core system functionality, privilege escalation, or partial data exposure.
Medium 4.0 – 6.9 Requires specific conditions or a complex exploitation environment; affects limited functionality or non‑critical sensitive information.
Low 0.1 – 3.9 Extremely difficult to exploit; causes only minor impact on availability or confidentiality.
CRA Article 11: 24/72‑Hour Mandatory Reporting Mechanism
In accordance with CRA requirements, for "Actively Exploited Vulnerabilities" or "vulnerabilities causing major security incidents":
24‑Hour Early Warning: Submit an early warning to the EU CSIRT coordinator and ENISA within 24 hours of confirmation of active exploitation.
72‑Hour Vulnerability Notification: Submit a detailed analysis report within 72 hours, including a risk assessment and remediation plan.
Final Analysis Report: Submit a comprehensive summary containing a root cause analysis within 14 days after the release of the patch or mitigation solution.
Get in Touch

Contact our friendly customer service team for any questions, concerns, or suggestions. We'd love to hear from you.


Headquarters Hotline: +86 755 61218391

Headquarters Email: info@saswell.com

Tech Support Email: support@saswell.com

CONTACT US
If you have questions or suggestions,please leave us a message,we will reply you as soon as we can!
Contact Us
SUBMIT NOW
Subscribe to Our Emails
Never miss SASWELL hot deals, news, and updates tailored for you.