1.Scope
This policy applies to:
- All Reolink camera models, excluding those that have reached end-of-life status.
- Reolink App, PC Client, VMS client.
- Reolink web application.
2.How to Report a Vulnerability
There are two ways to report vulnerabilities:
(1)Email: support@reolink.com (Sensitive information is recommended to be encrypted using PGP. Contact the support center to obtain the PGP public key)
(2) Submit the form online: Create a technical support ticket on our official website: https://support.reolink.com/requests/
3.Recommended Report Content
To help us quickly verify and remediate vulnerabilities, please include the following information in your report:
- Report title: Please add "[Report Vulnerability]" to help us identify and prioritize your submission.
- Product identification: The affected product model, firmware version, or URL.
- Vulnerability type: Unauthorized access, sensitive information leakage, etc.
- Verification evidence (PoC): The specific steps to reproduce the vulnerability, along with supporting evidence such as screenshots or videos.
- Potential impact: Your assessment of the potential impact of the vulnerability on users.
4.Review of Your Report
(1) We will acknowledge receipt of your report within 3 working days and start our evaluation process.
(2) You will receive a response within 7 working days. If necessary, we will contact you to request additional information or clarify details.
Typically reported vulnerabilities will be remediated within 3 months. The actual timeline depends on the difficulty and complexity of the vulnerability. The remediation progress and status will be updated to you via email.
5.Responsible Disclosure
We appreciate your efforts in reporting potential security vulnerabilities in Reolink products. To encourage responsible reporting, Reolink will not pursue legal action against you or request law enforcement investigation, provided that you follow the Responsible Disclosure Guidelines below:
- Avoid privacy violations, destruction of data, and interruption or degradation of our services.
- Do not modify or access data that does not belong to you.
- Keep information about any vulnerabilities you've discovered confidential between yourself and Reolink until we have resolved the issue.
- Immediately cease any activities that you know or reasonably believe to be illegal.
Reolink attaches great importance to product security. We may offer certain rewards based on the value of the reported vulnerabilities.