Welcome to eufy Vulnerability Management Program !

 

Vulnerability Management Program

As a security product provider, we take users’ privacy and data security very seriously. We will regularly check and track the vulnerabilities on eufy products and the status of public open-source components or components from component vendors and third-party vendors.
In addition to our efforts, we also hope that more people will participate. Whether you are a user of eufy products, a software developer, or a security researcher, you are an essential part of this program.
If you have discovered a vulnerability in an eufy product or have a security incident to report, please share your discovery with us.
Your discovery will be acknowledged and assessed promptly. Once vulnerabilities are confirmed, a remediation plan will be formulated.

Writing Guidelines

A high-quality vulnerability report is great to help us confirm and address an issue more quickly, and could help you receive an eufy Security Bounty reward.
A complete report includes:

  • A detailed description of the issue(s) and the behavior you observed, as well as the behavior that you expected
  • A numbered list of steps required to reproduce the issue
  • A reliable exploit for the issue you are reporting
  • Details of any related issues or variants

Eufy strongly recommends including a working exploit, rather than a basic proof of concept. We accept reports without this information, but reports with more details typically receive higher bounty rewards. If your report doesn’t include the necessary information to allow us to reproduce the issue, we may not be able to accept your report or evaluate it for a bounty. In addition, you must meet the following requirements:

  • You must be the first party to report the issue directly to eufy Product Security on the web or by email.
  • Your report must be clear and detailed and must include a reliable way to reproduce the issue, such as a working exploit.
  • You must not disclose the issue publicly before eufy releases an update with a security advisory for the report.
How to submit your research
If you believe you have discovered a security vulnerability that affects eufy devices, software, services, or eufy-owned web servers, please report it to us.
Anyone can submit a report, including security researchers, developers, and customers.
We make it a priority to resolve security and privacy issues as quickly as possible. Please note that for the protection of our customers, eufy doesn’t disclose or confirm security issues until our investigation is complete and any necessary updates are generally available.
Alternatively, you can email your report to [email protected].
Please note that if you submit your report via email, you will not be able to track progress online.