Discovered a security vulnerability?
Tell us about it
At Ei Electronics we realise that security is a process and not a destination. So If you have discovered something you believe to be a security vulnerability effecting or products or process please report it via
security@eielectronics.com.
We treat all reports with high priority and investigate all issues directly with the reporter as quickly as possible. When you make a report, please do so in English via
security@eielectronics.com and include the following information if applicable:
Target – Ei Electronics server identified by IP address, hostname, URL and so forth or the Ei Electronics product, including version number.
Type of issue – the type of vulnerability (e.g. according to OWASP, such as cross-site scripting, buffer overflow, SQL injection, etc.) and include a general description of the vulnerability.
Proof-of-concept and/or URL demonstrating the vulnerability – a demonstration of the vulnerability that shows how it works. Examples include:
- URL containing payload – e.g. XSS in GET request parameters
- Link to general checker – e.g. SSL vulnerabilities
- Video – generally useable (if uploading to a streaming service, please mark it as private)
- Please provide as detailed description as you can, or send us a combination of any of the previous choices.
We warmly welcome any recommendations on how to fix the vulnerability, if applicable.
This policy is designed to be compatible with common good practice among well-intentioned security researchers. It does not give you permission to act in any manner that is inconsistent with the law, or which might cause the Ei Electronics to be in breach of any of its legal obligations, including but not limited to (as updated from time to time):
The General Data Protection Regulation 2016/679 (GDPR) and the Data Protection Act 2018
Ei Electronics affirms that it will not seek prosecution of any security researcher who reports any security vulnerability on an Ei Electronics service or system, where the researcher has acted in good faith and in accordance with this disclosure policy.