Last Updated: 2026-05-20
Our company is committed to ensuring the security and stability of our products and service systems. We welcome collaboration from partners and independent security researchers to report any vulnerabilities that may affect the security of our products or services to our Product Security Incident Response Team (PSIRT) in accordance with this policy.
Any unauthorized errors, defects, vulnerabilities, or other issues directly affecting the operation of products or the security of services.
This policy applies to all products and servers providing external services for the company.
Security researchers can report vulnerabilities through the following methods: Please send an email to [email protected] to submit information. If you wish to protect your submitted content, please download and use this PGP key.
To provide an effective response, vulnerability reports should include the following information:
The company will acknowledge the receipt of the vulnerability report within one business day. After receiving the vulnerability report, the company will assess the vulnerability, following the Common Vulnerability Scoring System (CVSS). The assessment timeframe depends on factors such as severity, complexity, and scope of impact. Once the vulnerability is confirmed as valid, the company will develop a remediation plan within 30 days and provide a solution within 90 days of issue confirmation. After solution confirmation, the reporter will be notified, and the reporter can apply for a CVE ID. After CVE ID confirmation, the company will publicly disclose the issue and the solution on the website, including firmware version information.
DrayTek does not currently provide monetary rewards or operate a public bug bounty program for vulnerability submissions. Nevertheless, we highly value responsible disclosures from the security research community. Contributions that assist in improving the security of DrayTek products and services may be formally acknowledged, including recognition in security advisories, CVE disclosures, or other public communications, at DrayTek’s discretion.
The company reserves the right to handle vulnerability reports at its discretion, including deciding whether to fix the vulnerability, the time to fix the vulnerability, and the method of providing rewards. The company reserves the right to modify this policy. The final interpretation of this policy belongs to the company.