Welcome to the Queclink Security Center. As a leading company in the IoT industry, we place great importance on product security and the confidentiality of personal data. Security is a core principle of our product design. We are committed to working with the global security community to responsibly identify, address, and disclose vulner abilities, to protect our users' data and privacy.
Queclink takes all security issues seriously and will respond to and address promptly. If you discover any potential security vulnerabilities in our products, please contact our security team.
We will acknowledge your report within 2 working days and provide appropriate solutions within 7 working days. We will keep you updated throughout the process until the issue is fully resolved. We accept anonymous vulnerability reports; however, without your contact details, we may be unable to share progress updates and solutions with you.
Before publicly disclosing a vulberability, we will set a remediation timeline based on its severity. The timelines are outlined in the table below:
Assess each vulnerability independently using CVSS v3
Determine the severity level and applicable remediation timeline below:
| Severity | CVSS Score | Remediation SLA |
|---|---|---|
| Critical | 9.0-10.0 | ≤ 7 days to implement a fix or mitigation measures |
| High | 7.0-8.9 | ≤ 30 days |
| Medium | 4.0-6.9 | ≤ 90 days |
| Low | 0.1-3.9 | Fix in the next regular release |
Please include the following information in your report to help us resolve the vulnerability promptly:
Affected product(s) and software version(s);
Vulnerability overview;
Issue description and potential impact (e.g., arbitrary code execution or information disclosure);
Instructions to reproduce the issue (Proof of Concept)
You can also report vulberabilities by emailing
security@queclink.com.
