Security · CRA Article 14

Vulnerability Disclosure

Bamboo Dynamics is committed to the security of our products. If you identify a potential security vulnerability, we appreciate coordinated disclosure and are committed to working with you to address it swiftly.

This page fulfils the vulnerability reporting obligation under EU Cyber Resilience Act (CRA) Article 14. Bamboo Dynamics will report actively exploited vulnerabilities to the relevant national authority (ENISA) within 24 hours of discovery.

Coordinated Disclosure Process

We follow a structured responsible vulnerability disclosure process, with clear timelines, defined communication steps, and transparent expectations at every stage.

01

Submit Your Report

Fill out the form below or email sales@bamboo-dynamics.com. Include as much detail as possible to help us triage and reproduce the issue.

02

Acknowledgement

We will acknowledge receipt of your report within 72 hours and provide a tracking reference number.

03

Assessment & Fix

Our engineering team investigates and develops a fix. We will keep you updated on progress and expected resolution timeline.

04

Coordinated Disclosure

We coordinate the public disclosure timeline with you. After the fix is available, we publish a security advisory crediting your discovery.

≤ 72 hours
Acknowledgement
after submission
≤ 10 days
Initial Assessment
severity classification
≤ 90 days
Resolution Target
for critical / high severity

What to include in your report

The more detail you provide, the faster we can assess and fix the issue. The fields below help.

Affected Product(s)
e.g. BRT555, SWG1610, TCI-205Z
Firmware / Software Version
e.g. v2.3.1 — check the product web UI or label
Vulnerability Type
e.g. Buffer overflow, authentication bypass, default credentials
Attack Vector
Network / Local / Physical / Adjacent
Description
Clear explanation of the vulnerability and its potential impact
Steps to Reproduce
Step-by-step instructions to trigger the issue
CVE / CWE Reference
If you have already requested a CVE ID, include it here
Suggested Severity
Critical / High / Medium / Low — CVSS score if available

Submit a Vulnerability Report

Prefer email? Send your report directly to sales@bamboo-dynamics.com

Your submission is treated as confidential. We do not share reporter information without explicit consent.

In Scope

  • Bamboo Dynamics hardware products (BRT, SWG, BGS, TRUE MDR series)
  • Embedded firmware and web management interfaces
  • Bamboo Dynamics official web properties (bamboo-dynamics.com)
  • Authentication, authorization, and access control issues
  • Remote code execution and command injection
  • Sensitive data exposure or insecure default configurations

Out of Scope

  • Denial of service (DoS/DDoS) attacks against our infrastructure
  • Physical attacks requiring direct hardware access
  • Social engineering or phishing against Bamboo employees
  • Issues in third-party products or services we use
  • Vulnerabilities in end-of-life products (EOL > 3 years)
  • Theoretical vulnerabilities without a proof of concept

Safe Harbour

Bamboo Dynamics considers good-faith security research to be a valuable contribution. We will not pursue civil or criminal action against researchers who discover and report vulnerabilities responsibly, provided the research does not involve accessing, modifying, or deleting customer data; disrupting production systems; or violating applicable laws. We ask that you give us reasonable time to respond before any public disclosure.

Questions about this policy?

For questions about our security practices or this disclosure policy, contact us at sales@bamboo-dynamics.com