VTech Coordinated Vulnerability Disclosure Policy
VTech is committed to helping protect the
security, safety and privacy of customers and users of VTech products with
digital elements. This Policy establishes VTech’s coordinated vulnerability
disclosure process for receiving, assessing, remediating and, where
appropriate, disclosing information about potential vulnerabilities reported by
internal and external sources.
This Policy supports VTech’s
vulnerability-handling obligations under applicable law, including Regulation
(EU) 2024/2847 (the Cyber Resilience Act or CRA), where applicable. It does not
replace VTech’s internal product-security, incident-response,
regulatory-notification, software-update, privacy or supplier-management
procedures.
This Policy applies to potential
vulnerabilities affecting VTech products with digital elements and related
services made available by VTech, including relevant hardware, software,
firmware, mobile applications, online services and remote data-processing
solutions that are designed or developed by or on behalf of VTech and are
necessary for those products to perform their functions.
This Policy does not authorise testing of
assets owned or controlled exclusively by third parties. However, where a
report concerns a third-party component, library, service or supplier product
incorporated into or necessary for a VTech product, VTech may coordinate with
the relevant supplier, maintainer, computer security incident response team
(CSIRT), The European Union Agency for Cybersecurity (ENISA), competent
authority or other appropriate party to validate, remediate and disclose the
vulnerability.
Subject to this Policy and applicable law,
VTech authorises good-faith security research directed solely at identifying
and reporting potential vulnerabilities in in-scope assets. VTech will not
knowingly pursue civil claims or refer such good-faith, authorised research for
law-enforcement action solely because of that research.
This authorisation applies only where the
researcher complies with this Policy, acts proportionately to avoid harm, and
promptly reports the vulnerability to VTech. It does not authorise conduct that
is unlawful, causes or risks material harm, infringes third-party rights, or is
outside the stated scope. VTech cannot waive rights held by third parties or
override the requirements of applicable law.
If a researcher is uncertain whether
proposed activity is within scope or authorised, the researcher should contact
VTech before proceeding at VulnerabilityReporting@vtech.com.
To participate in the coordinated
vulnerability disclosure process, researchers must:
·
comply with all applicable laws
and this Policy;
·
use only accounts owned by the
researcher, designated test accounts, or accounts for which the researcher has
express written permission;
·
avoid accessing, collecting,
copying, altering, transmitting, retaining or deleting VTech, customer or user
data, except to the minimum extent strictly necessary to demonstrate the
vulnerability and only where lawful;
·
immediately stop further access
or collection if personal, confidential or user data is inadvertently
encountered, preserve only the minimum evidence necessary, and promptly notify
VTech through a secure channel;
·
avoid interruption, degradation
or destruction of services; denial-of-service, resource-exhaustion and similar
testing are prohibited unless VTech expressly authorises them in writing;
·
not exfiltrate data, introduce
malware, establish persistence, pivot to other systems, or exploit a
vulnerability beyond the minimum needed to establish its existence;
·
not use social engineering,
physical attacks, threats, extortion or coercion;
·
not publicly disclose
vulnerability details before coordinating with VTech under section 7; and
·
keep vulnerability information
confidential until VTech and the reporter agree a disclosure timetable, subject
to applicable law and the public interest.
Reports should be submitted to
VulnerabilityReporting@vtech.com. Reports may be submitted anonymously.
Researchers should use the subject line
“URGENT — suspected active exploitation” where they have a reasonable basis to
believe that a vulnerability is being actively exploited or creates an
immediate material risk to users.
To enable timely triage, reports should,
where available, include:
·
identification of the affected
VTech product, product version, component, firmware/software version, service,
domain or application;
·
where relevant, the country or
channel through which the product was purchased and the location in which the
issue was observed;
·
a description of the
vulnerability, its potential impact and any information indicating actual or
suspected active exploitation;
·
clear, reproducible steps,
proof-of-concept code, logs, screenshots or other evidence sufficient to
validate the issue, while minimising disclosure of personal or confidential
data;
·
any known mitigation,
workaround, proposed fix, affected third-party component or related identifier;
and
·
a secure contact method and any
preferred acknowledgement or disclosure attribution, if the reporter wishes to
be contacted or credited.
On receipt of a report, VTech will:
·
acknowledge receipt as soon as
reasonably practicable;
·
assess whether the report is
within scope and whether it indicates suspected active exploitation, a severe
incident or an urgent risk to users;
·
validate and analyse the issue,
including its severity, affected products and versions, exploitability,
potential impact, and any affected third-party components;
·
prioritise, develop, test and
deploy appropriate corrective or mitigating measures, including security
updates, workarounds, configuration changes, customer guidance or other
remediation measures, as appropriate;
·
coordinate with affected
suppliers, maintainers, CSIRTs, competent authorities and other relevant
parties where necessary for effective remediation;
·
provide status updates to the
reporter where reasonably practicable, taking account of the nature and
sensitivity of the report; and
·
document assessment,
remediation, disclosure and any decision to delay public disclosure in
accordance with applicable internal procedures.
VTech aims to provide an acknowledgement
within 24-hour upon receiving of a report and an initial triage outcome or
material status update where reasonably practicable. Actual response and
remediation times depend on severity, complexity, exploitability, affected
products, availability of mitigations and the information provided.
VTech asks reporters not to disclose
vulnerability details publicly before VTech has had a reasonable opportunity to
validate, assess and remediate the issue. VTech will work in good faith with
the reporter to agree a coordinated disclosure timetable, taking into account
exploitability, active exploitation, affected users, availability of
mitigation, availability of a security update and the public interest.
Once a security update or other corrective
measure is made available, VTech will share and publicly disclose information
about the fixed vulnerability in an appropriate security advisory, unless VTech
reasonably determines and documents that the cybersecurity risks of immediate
public disclosure outweigh the security benefits. In that case, VTech may delay
publication for no longer than necessary to manage those risks and, where
appropriate, provide affected users a reasonable opportunity to apply the
relevant patch or mitigation first.
A security advisory will, as appropriate,
include:
·
a description of the
vulnerability;
·
the affected product, component
and version or version range;
·
the vulnerability’s impact and
severity;
·
clear, accessible instructions
enabling users to remediate or mitigate the issue; and
·
information about the relevant
security update, workaround or other corrective measure.
VTech may acknowledge or credit a reporter
in a security advisory only with the reporter’s consent and subject to
applicable law, security considerations and the reporter’s stated preferences.
VTech will assess whether a report concerns
an actively exploited vulnerability or a severe incident affecting the security
of a VTech product with digital elements. Where applicable, VTech will make
notifications through the CRA Single Reporting Platform and to the relevant
recipients within the deadlines required by Regulation (EU) 2024/2847 and other
applicable law.
This public reporting channel does not
replace VTech’s regulatory-notification processes. VTech will consider, where
applicable, to provide for an early-warning assessment and escalation capable
of supporting, notification within 24 hours of awareness, a full notification
within 72 hours, and a final report within 14 days for an actively exploited
vulnerability, or within one month for a severe incident, covering the
incident, its root cause and the mitigating measures taken.
VTech may report or share vulnerability or
incident information with competent authorities, CSIRTs, ENISA, suppliers,
maintainers, service providers or other appropriate parties where required by
law or reasonably necessary to investigate, remediate, coordinate disclosure or
protect users.
In addition to notifying the competent
CSIRT and ENISA, VTech will inform affected users, without undue delay, that a
vulnerability or incident has been identified that may affect the security of
their product, together with any mitigation steps users can take, even where a
permanent security update is not yet available.
Where a reported issue affects a
third-party component, library, vendor or service, VTech may share the minimum
necessary information with that party or an appropriate coordinator to support
validation, remediation and coordinated disclosure. Where reasonably
practicable, VTech will take account of the sensitivity of the report and the
reporter’s contact preferences. VTech may make such disclosures without prior
notice where necessary to protect users, comply with law or manage material
cybersecurity risk.
VTech will process personal data contained
in vulnerability reports for vulnerability management, product security,
incident response, regulatory compliance, legal obligations and the protection
of VTech, its users and other affected persons. VTech will handle reports in
accordance with its privacy policy.
Researchers should not include unnecessary
personal data, confidential information, credentials or sensitive data in a
report. VTech may share information contained in a report with relevant VTech
personnel, group companies, service providers, affected suppliers or
maintainers, CSIRTs, competent authorities or law-enforcement bodies where
permitted or required by law and necessary for the purposes described in this
Policy and the Privacy Notice.
VTech will review the Policy regularly and
following material changes to applicable requirements, VTech products, security
operations or lessons learned from vulnerability handling.
VTech maintains internal roles, procedures,
records, training and oversight arrangements to support implementation and
enforcement of this Policy, vulnerability handling throughout relevant support
periods, and continuous improvement of product security.
Questions about this Policy or uncertainty
about authorised research should be sent to VulnerabilityReporting@vtech.com.
This Policy does not create a contractual
obligation, waive any legal right or remedy, or authorise any activity outside
the scope expressly stated in this Policy. Nothing in this Policy limits
VTech’s ability to take action in relation to conduct that is unlawful,
malicious, reckless, fraudulent, extortionate, harmful, or inconsistent with
this Policy.