1 Introduction
引言
Sunell ("we", "us") is committed to the security of our products and the people who rely on them. We welcome reports of potential security vulnerabilities from security researchers, customers and members of the public. This Coordinated Vulnerability Disclosure (CVD) policy explains what is in scope, how to report a vulnerability to us, how we will respond, and how we coordinate public disclosure.
Sunell(“我们”)致力于保障我们产品及依赖这些产品的人员的安全。我们欢迎安全研究人员、客户和公众报告潜在的安全漏洞。本协调漏洞披露(CVD)策略说明了适用范围、如何向我们报告漏洞、我们将如何响应,以及我们如何协调公开披露。
2 Scope
范围
This policy applies to the following products and services: IP cameras (incl. PTZ, fisheye, thermal, explosion-proof, corrosion-proof, ANPR, panoramic), recorders (NVR/DVR/XVR), modules, VMS, and Sunell mobile/cloud applications and services.
本策略适用于以下产品和服务:[列出适用范围内的产品、服务和版本]。
Eligibility for remediation: products and services receive security fixes while they are within their defined support period. For example, a product is not eligible to receive remediation once it is beyond its published end-of-support date.
修复资格:产品和服务在其既定支持周期内可获得安全修复。例如,产品一旦超出其公布的支持终止日期,即无资格获得修复。
The following are out of scope (examples): third-party services we do not operate; findings that are already public; reports with no demonstrable security impact; volumetric denial-of-service testing; and social-engineering of our staff or customers.
以下内容不在范围之内(示例):我们不运营的第三方服务;已经公开的发现;无法证明具有安全影响的报告;大流量拒绝服务测试;以及针对我们员工或客户的社会工程。
3 How to report a vulnerability
如何报告漏洞
Please report potential vulnerabilities through one of the following channels:
请通过以下渠道之一报告潜在漏洞:
• Email: security@sunellsecurity.com (preferred).
• 电子邮件:security@sunellsecurity.com(首选)。
• Web form: https://www.sunellsecurity.com/company/trust-center/.
• 网页表单:https://www.sunellsecurity.com/company/trust-center/。
• Telephone: +86(755)-2675-4336, via our customer service, for those who cannot use a written channel.
• 电话:+86(755)-2675-4336,通过我们的客户服务,供无法使用书面渠道者使用。
We provide more than one channel so that reporters can choose a method that suits them, including by telephone where a written channel is not accessible.
我们提供不止一种渠道,以便报告者选择适合自己的方式,包括在书面渠道不可用时通过电话报告。
4 Secure and anonymous reporting
安全与匿名报告
To protect sensitive vulnerability information while it is being exchanged:
为在交换过程中保护敏感的漏洞信息:
• Our web form is served over HTTPS.
• 我们的网页表单通过 HTTPS 提供。
• You may encrypt email to us using our PGP key (fingerprint E467 C567 3083 2274 EE72 4505 2525 8782 B2F3 5DE8). Download the public key (.asc): https://www.sunellsecurity.com/.well-known/sunell-security-pgp.asc. The same file is listed in https://www.sunellsecurity.com/.well-known/security.txt.
• 您可以使用我们的 PGP 密钥(指纹 E467 C567 3083 2274 EE72 4505 2525 8782 B2F3 5DE8)对发给我们的邮件加密。公钥文件(.asc)下载:https://www.sunellsecurity.com/.well-known/sunell-security-pgp.asc。密钥位置亦列于 https://www.sunellsecurity.com/.well-known/security.txt。
• PGP public key file (.asc): https://www.sunellsecurity.com/.well-known/sunell-security-pgp.asc
• PGP 公钥文件(.asc):https://www.sunellsecurity.com/.well-known/sunell-security-pgp.asc
You may report anonymously. If you would like a response, please give us a contact address or an alias.
您可以匿名报告。若希望得到回复,请向我们提供联系地址或别名。
We will still accept reports sent through less secure channels - please do not let the lack of encryption stop you from reporting.
我们仍会接受通过较不安全渠道发送的报告——请不要因为缺少加密而放弃报告。
5 What to include in your report
报告中应包含的内容
To help us validate and fix the issue quickly, please include as much of the following as you can:
为帮助我们快速验证和修复问题,请尽可能多地包含以下内容:
• Product identification - the affected product or service name, the affected version(s), and the platform or environment (OS, hardware) where applicable.
• 产品标识——受影响的产品或服务名称、受影响的版本,以及平台或环境(操作系统、硬件,如适用)。
• Vulnerability description - what the issue is and where it exists, and its type or class (e.g., buffer overflow, SQL injection, improper authentication).
• 漏洞描述——问题是什么、存在于何处,及其类型或类别(例如缓冲区溢出、SQL 注入、不当鉴权)。
• Impact - the potential impact if the issue is exploited (confidentiality, integrity or availability), and a severity assessment or CVSS score if you have one.
• 影响——问题被利用时的潜在影响(保密性、完整性或可用性),以及严重性评估或 CVSS 分值(如有)。
• Reproduction steps - step-by-step instructions to reproduce the issue, and proof-of-concept code or technical evidence if available.
• 复现步骤——复现该问题的分步说明,以及概念验证代码或技术证据(如有)。
• Discovery information - the date you found the issue and how (testing method, tool, or accidental finding).
• 发现信息——您发现问题的日期及方式(测试方法、工具或偶然发现)。
• Your contact information - your name or alias (you may remain anonymous) and a channel for follow-up.
• 您的联系信息——您的姓名或别名(可匿名)以及用于后续跟进的渠道。
• Disclosure intent - whether you intend to publish your findings, and any date you are working toward.
• 披露意向——您是否打算公开您的发现,以及您所争取的任何日期。
6 What you can expect from us
您可期待我们做到
After you submit a report, we will:
在您提交报告后,我们将:
• acknowledge receipt within 3 business days and assign a tracking reference;
• 在 3 个工作日内确认接收并分配跟踪编号;
• aim to triage and validate your report within 7 business days, and contact you if we need more information;
• 力争在 7 个工作日内对您的报告进行定级和验证,并在需要更多信息时与您联系;
• keep you informed of our progress at reasonable intervals;
• 以合理的间隔让您了解我们的进展;
• aim to deliver a resolution within 90 days, depending on complexity and any third parties involved;
• 视复杂程度及所涉任何第三方而定,力争在 90 天内交付解决方案;
• notify you when the vulnerability has been remediated, and may invite you to confirm that the fix resolves it.
• 在漏洞被修复时通知您,并可能邀请您确认该修复已解决问题。
7 Coordinated disclosure
协调披露
We follow a coordinated disclosure approach:
我们采用协调披露的方式:
• We ask that you give us a reasonable opportunity to remediate the issue before disclosing it publicly.
• 我们请您在公开披露之前给予我们合理的机会来修复问题。
• We will not publicly disclose details of a reported vulnerability before it has been addressed; any public disclosure will be coordinated and agreed between you and us.
• 在所报告的漏洞被处理之前,我们不会公开披露其细节;任何公开披露都将由您与我们协调并达成一致。
• Where appropriate we agree an embargo period. Embargo timelines can be adjusted case by case by mutual agreement, including where a coordinator or other vendors are involved.
• 在适当情况下,我们会约定禁披期。禁披时限可在双方同意的情况下逐案调整,包括在涉及协调者或其他供应商时。
• When a fix is released, we publish a security advisory and, where appropriate, request a CVE identifier and submit the information to the EU Vulnerability Database (EUVD).
• 在发布修复时,我们会发布安全公告,并在适当情况下申请 CVE 编号并将信息提交至欧盟漏洞数据库(EUVD)。
8 Where to find our security advisories
在何处查找我们的安全公告
When a vulnerability has been remediated, we publish a security advisory so that users can assess whether they are affected and how to update. You can find our advisories at:
当漏洞被修复后,我们会发布安全公告,以便用户评估自身是否受影响以及如何更新。您可在以下位置找到我们的公告:
• Security advisory page: https://www.sunellsecurity.com/company/trust-center/.
• 安全公告页面:https://www.sunellsecurity.com/company/trust-center/。
• Machine-readable advisories (CSAF 2.0): https://www.sunellsecurity.com/.well-known/csaf/.
• 机器可读公告(CSAF 2.0):https://www.sunellsecurity.com/.well-known/csaf/。
• Product release notes and update notifications delivered through the product or its update channel.
• 通过产品或其更新渠道提供的产品发行说明和更新通知。
• CVE records (where a CVE has been assigned) and the EU Vulnerability Database (EUVD).
• CVE 记录(在已分配 CVE 的情况下)以及欧盟漏洞数据库(EUVD)。
To be notified of new advisories, you can subscribe via our security mailing list by contacting security@sunellsecurity.com.
如需接收新公告通知,您可通过联系 security@sunellsecurity.com 订阅我们的安全邮件列表。
9 Confidentiality and recognition
保密与致谢
We treat vulnerability reports as confidential. We will not share the personal information you provide with third parties without your explicit consent, except where required by law.
我们将漏洞报告视为机密。未经您的明确同意,我们不会将您提供的个人信息与第三方共享,法律要求的情形除外。
With your permission, we are happy to credit you for your discovery in our advisory or on our acknowledgements page. Let us know if you would prefer to remain anonymous.
在征得您同意的情况下,我们乐于在公告或致谢页面中为您的发现署名致谢。若您希望保持匿名,请告知我们。
10 Safe harbour and good-faith research
安全港与善意研究
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you.
若您在研究过程中善意努力遵守本策略,我们将视您的研究为获得授权,将与您合作以迅速理解和解决问题,并且不会针对您提起或支持法律诉讼。
Good-faith research means, among other things, that you:
善意研究尤其意味着您:
• only interact with systems or accounts you own or have explicit permission to test;
• 仅与您拥有或获明确许可进行测试的系统或账户交互;
• avoid privacy violations, destruction of data, and any degradation of our services (for example, no denial-of-service testing);
• 避免侵犯隐私、破坏数据以及对我们服务造成任何降级(例如不进行拒绝服务测试);
• access only the minimum data necessary to demonstrate the issue, and do not store, share or use it;
• 仅访问证明该问题所必需的最少数据,且不予存储、共享或使用;
• give us a reasonable time to resolve the issue before any disclosure.
• 在任何披露之前给予我们合理的时间来解决问题。
11 Policy changes
策略变更
We may update this policy from time to time. The current version and its publication date are shown in Document control above; material changes are recorded below.
我们可能会不时更新本策略。当前版本及其发布日期见上方“文件控制”;重大变更记录于下方。
Version 版本 | Changed by 变更人 | Date 日期 | Reason 原因 |
1.0 | Corey Zhou | 2026-09-02 | Initial version 初始版本 |
