{"id":15744,"date":"2026-09-03T07:19:33","date_gmt":"2026-09-03T12:19:33","guid":{"rendered":"https:\/\/www.avire-global.com\/en-us\/report-security-vulnerability\/"},"modified":"2026-09-03T07:19:33","modified_gmt":"2026-09-03T12:19:33","slug":"report-security-vulnerability","status":"publish","type":"page","link":"https:\/\/www.avire-global.com\/en-us\/report-security-vulnerability\/","title":{"rendered":"Report Security Vulnerability"},"content":{"rendered":"\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--fluid-40-80);margin-bottom:var(--wp--preset--spacing--fluid-40-80)\">\n<h1 class=\"wp-block-heading\">Report a Security Vulnerability<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">AVIRE welcomes reports of security vulnerabilities affecting our products, firmware, cloud services and websites. We operate a Coordinated Vulnerability Disclosure (CVD) process: if you believe you have found a vulnerability, please tell us first and give us the opportunity to investigate and remediate it before the issue is made public.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reports made in good faith are welcome from anyone \u2014 customers, security researchers, partners, installers and end users alike. AVIRE will not pursue legal action against researchers who investigate and report vulnerabilities responsibly and in line with our Coordinated Vulnerability Disclosure Policy (reference <strong><a href=\"https:\/\/www.avire-global.com\/wp-content\/uploads\/2026\/09\/AV-CVD-001-PUB-Coordinated-Vulnerability-Disclosure-Policy-Public-Summary.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">AV-CVD-001<\/a><\/strong>).<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--fluid-16-32);margin-bottom:var(--wp--preset--spacing--fluid-16-32)\">\n<h2 class=\"wp-block-heading\">How to contact us<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Email our security team at <a href=\"mailto:security@avire-global.com\">security@avire-global.com<\/a>, or use the reporting form at the bottom of this page. Both routes reach the same team.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your report contains sensitive technical detail, exploit code or customer data, please encrypt it. Our PGP public key is published at <a href=\"https:\/\/www.avire-global.com\/.well-known\/security.asc\" target=\"_blank\" rel=\"noreferrer noopener\">security.asc<\/a>.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--fluid-16-32);margin-bottom:var(--wp--preset--spacing--fluid-16-32)\">\n<h2 class=\"wp-block-heading\">What to include in your report<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The more detail you can give us, the faster we can triage and reproduce the issue. Where possible, please tell us:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The affected product, model and firmware or software version.<\/li>\n\n\n\n<li>A description of the vulnerability and the impact you believe it could have.<\/li>\n\n\n\n<li>Steps to reproduce the issue, or a proof of concept.<\/li>\n\n\n\n<li>Any supporting evidence such as logs, configuration details or screenshots.<\/li>\n\n\n\n<li>How you would like to be contacted, and whether you wish to be credited publicly.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Please do not access, modify or delete data belonging to other people, and do not run tests that could disrupt a live installation, or a product&#8217;s alarm or emergency communication function, or put building occupants at risk.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--fluid-16-32);margin-bottom:var(--wp--preset--spacing--fluid-16-32)\">\n<h2 class=\"wp-block-heading\">Good Faith Research<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">AVIRE supports good-faith security research. Vulnerabilities discovered and reported in good faith, for the purpose of testing, investigating or correcting a security flaw and without malicious intent, are handled under our CVD Policy. We will not pursue legal action against researchers who act in good faith, comply with our CVD Policy (including the testing rules), avoid privacy violations and service disruption, and do not disclose a vulnerability publicly before a coordinated disclosure has taken place.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--fluid-16-32);margin-bottom:var(--wp--preset--spacing--fluid-16-32)\">\n<h2 class=\"wp-block-heading\">How we will respond<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>We acknowledge receipt of every report within <strong>1 business day<\/strong>.<\/li>\n\n\n\n<li>We assess and triage the report, and keep you informed while we investigate.<\/li>\n\n\n\n<li>Where a fix or mitigation is needed, we work on it and coordinate the disclosure timeline with you.<\/li>\n\n\n\n<li>If you have consented, we credit you as the reporter in the related security advisory.<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--fluid-16-32);margin-bottom:var(--wp--preset--spacing--fluid-16-32)\">\n<h2 class=\"wp-block-heading\">Coordinated Vulnerability Disclosure Policy (AV-CVD-001)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">AVIRE\u2019s Coordinated Vulnerability Disclosure Policy, document reference <strong><a href=\"https:\/\/www.avire-global.com\/wp-content\/uploads\/2026\/09\/AV-CVD-001-PUB-Coordinated-Vulnerability-Disclosure-Policy-Public-Summary.pdf\">AV-CVD-001<\/a><\/strong>, sets out the scope of this process, the information we need, how we handle reports, our response commitments and our disclosure principles.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--fluid-16-32);margin-bottom:var(--wp--preset--spacing--fluid-16-32)\">\n<h2 class=\"wp-block-heading\">security.txt (RFC 9116)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">AVIRE publishes a machine-readable security contact file in accordance with <a href=\"https:\/\/www.rfc-editor.org\/rfc\/rfc9116.html\" rel=\"nofollow noopener\" target=\"_blank\">RFC 9116<\/a>. It lists our security contact address, our PGP key and this reporting page, and is available at <a href=\"https:\/\/www.avire-global.com\/.well-known\/security.txt\" target=\"_blank\" rel=\"noreferrer noopener\">security.txt<\/a>.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--fluid-16-32);margin-bottom:var(--wp--preset--spacing--fluid-16-32)\">\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Submit a report<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use the form below to send your report straight to AVIRE\u2019s security team. Fields marked with * are required; everything else is optional and simply helps us triage faster.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Please do not include personal data relating to third parties, and do not attach live customer data. If your report is highly sensitive, email it to <a href=\"mailto:security@avire-global.com\" target=\"_blank\" rel=\"noreferrer noopener\">security@avire-global.com<\/a> encrypted with our PGP key instead.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-899dd54d wp-block-group-is-layout-constrained\" style=\"margin-top:var(--wp--preset--spacing--fluid-16-32);margin-bottom:var(--wp--preset--spacing--fluid-16-32); width: 600px;\">\n<div class=\"wp-block-group has-border-color has-border-border-color has-global-padding is-layout-constrained wp-container-core-group-is-layout-b743ac47 wp-block-group-is-layout-constrained\" style=\"border-width:1px;border-top-left-radius:16px;border-top-right-radius:16px;border-bottom-left-radius:16px;border-bottom-right-radius:16px;padding-top:var(--wp--preset--spacing--fluid-16-24);padding-right:var(--wp--preset--spacing--fluid-16-24);padding-bottom:var(--wp--preset--spacing--fluid-16-24);padding-left:var(--wp--preset--spacing--fluid-16-24)\">\n<div class=\"wp-block-contact-form-7-contact-form-selector\">\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f15743-o1\" lang=\"en-GB\" dir=\"ltr\" data-wpcf7-id=\"15743\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en-us\/wp-json\/wp\/v2\/pages\/15744#wpcf7-f15743-o1\" method=\"post\" class=\"wpcf7-form init\" aria-label=\"Contact form\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"15743\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.7\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"en_GB\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f15743-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/>\n<\/fieldset>\n<div class=\"wpcf7-turnstile cf-turnstile\" data-sitekey=\"0x4AAAAAACU4_lQBYY07UK2M\" data-response-field-name=\"_wpcf7_turnstile_response\"><\/div>\n\n<div class=\"field\">\n\t<p><label>Your name (optional)<\/label><br \/>\n<span class=\"wpcf7-form-control-wrap\" data-name=\"reporter-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text\" autocomplete=\"name\" aria-invalid=\"false\" placeholder=\"Your name\" value=\"\" type=\"text\" name=\"reporter-name\" \/><\/span>\n\t<\/p>\n<\/div>\n<div class=\"field\">\n\t<p><label>Contact email *<\/label><br \/>\n<span class=\"wpcf7-form-control-wrap\" data-name=\"reporter-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email\" autocomplete=\"email\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"email@example.com\" value=\"\" type=\"email\" name=\"reporter-email\" \/><\/span>\n\t<\/p>\n<\/div>\n<div class=\"field\">\n\t<p><label>Affected product \/ version<\/label><br \/>\n<span class=\"wpcf7-form-control-wrap\" data-name=\"affected-product\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text\" aria-invalid=\"false\" placeholder=\"Product, model and firmware or software version\" value=\"\" type=\"text\" name=\"affected-product\" \/><\/span>\n\t<\/p>\n<\/div>\n<div class=\"field\">\n\t<p><label>Description of the vulnerability *<\/label><br \/>\n<span class=\"wpcf7-form-control-wrap\" data-name=\"vulnerability-description\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"What is the issue, how can it be reproduced and what is the potential impact?\" name=\"vulnerability-description\"><\/textarea><\/span>\n\t<\/p>\n<\/div>\n<div class=\"field\">\n\t<p><label>Estimated severity (optional)<\/label><br \/>\n<span class=\"wpcf7-form-control-wrap\" data-name=\"severity\"><select class=\"wpcf7-form-control wpcf7-select cf7-placeholder\" aria-invalid=\"false\" name=\"severity\"><option value=\"\">-- Select --<\/option><option value=\"Low\">Low<\/option><option value=\"Medium\">Medium<\/option><option value=\"High\">High<\/option><option value=\"Critical\">Critical<\/option><option value=\"I do not know\">I do not know<\/option><\/select><\/span>\n\t<\/p>\n<\/div>\n<div class=\"field upload-field\">\n\t<p><label>Attachments (optional)<\/label><br \/>\n<span class=\"wpcf7-form-control-wrap\" data-name=\"report-attachment\"><input size=\"40\" class=\"wpcf7-form-control wpcf7-drag-n-drop-file d-none\" aria-invalid=\"false\" type=\"file\" multiple=\"multiple\" data-name=\"report-attachment\" data-type=\"pdf|txt|log|png|jpg|jpeg|gif|zip\" data-limit=\"10485760\" data-max=\"5\" data-id=\"15743\" data-version=\"free version 1.4.0\" accept=\".pdf, .txt, .log, .png, .jpg, .jpeg, .gif, .zip\" \/><\/span>\n\t<\/p>\n\t<p class=\"upload-help\"><br \/>\nScreenshots, logs or proof of concept \u00b7 Max 5 files, 10MB each \u00b7 PDF, TXT, LOG, PNG, JPG, GIF, ZIP\n\t<\/p>\n<\/div>\n<div class=\"field\">\n\t<p><span class=\"wpcf7-form-control-wrap\" data-name=\"credit-consent\"><span class=\"wpcf7-form-control wpcf7-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"credit-consent[]\" value=\"I consent to being publicly credited as the reporter in the related security advisory.\" \/><span class=\"wpcf7-list-item-label\">I consent to being publicly credited as the reporter in the related security advisory.<\/span><\/label><\/span><\/span><\/span>\n\t<\/p>\n<\/div>\n<p><span class=\"wpcf7-form-control-wrap\" data-name=\"acceptance\"><span class=\"wpcf7-form-control wpcf7-acceptance\"><span class=\"wpcf7-list-item\"><label><input type=\"checkbox\" name=\"acceptance\" value=\"1\" aria-invalid=\"false\" \/><span class=\"wpcf7-list-item-label\">I consent to my details being stored in reference to the GDPR. See <a href=\"https:\/\/www.avire-global.com\/en-us\/privacy-policies\/\" target=\"_blank\" rel=\"noopener\">privacy policy.<\/a><\/span><\/label><\/span><\/span><\/span>\n<\/p>\n<div class=\"buttons\">\n\t<p><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Submit report\" \/>\n\t<\/p>\n<\/div><input type=\"text\" class=\"wpcf7_hp_field\" name=\"wpcf7_hp_field\" value=\"\" tabindex=\"-1\" autocomplete=\"off\" \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Report a Security Vulnerability AVIRE welcomes reports of security vulnerabilities affecting our products, firmware, cloud services and websites. We operate a Coordinated Vulnerability Disclosure (CVD) process: if you believe you have found a vulnerability, please tell us first and give us the opportunity to investigate and remediate it before the issue is made public. Reports [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"wp-custom-template-legal-page","meta":{"_eb_attr":"","inline_featured_image":false,"footnotes":""},"class_list":["post-15744","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.avire-global.com\/en-us\/wp-json\/wp\/v2\/pages\/15744","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.avire-global.com\/en-us\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.avire-global.com\/en-us\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.avire-global.com\/en-us\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.avire-global.com\/en-us\/wp-json\/wp\/v2\/comments?post=15744"}],"version-history":[{"count":0,"href":"https:\/\/www.avire-global.com\/en-us\/wp-json\/wp\/v2\/pages\/15744\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.avire-global.com\/en-us\/wp-json\/wp\/v2\/media?parent=15744"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}