Coordinated Vulnerability Disclosure Policy
This policy explains how to report potential security vulnerabilities affecting aosu products and how aosu receives, assesses, remediates, and coordinates the disclosure of reported vulnerabilities.
This policy covers security vulnerabilities affecting aosu devices, firmware, software, mobile applications, cloud services, aosu-controlled websites, and third-party components integrated into aosu products. Independent third-party products or websites that are not integrated into or controlled by aosu are outside the scope of this policy.
Vulnerability Management Program
As a security product provider, we take users' privacy and data security very seriously. We will regularly check and track the vulnerabilities on aosu products and the status of public open-source components or components from component vendors and third-party vendors. In addition to our efforts, we also hope that more people will participate. Whether you are a user of aosu products, a software developer, or a security researcher, you are an essential part of this program. If you have discovered a vulnerability in an aosu product or have a security incident to report, please share your discovery with us.
Information to Include
To help us assess the issue more efficiently, please include the following information, where available:
- The affected product/model and firmware, App, or software version;
- A detailed description of the issue and its potential impact;
- Steps to reproduce the issue;
- Relevant logs, screenshots, videos, or other supporting materials;
- Details of any related issues, known mitigations, or workarounds.
How to Submit Your Research
Potential security vulnerabilities may be reported to g-sec@aosulife.com. This mailbox is monitored by the aosu Product Security Team and may be used to submit vulnerability reports and receive related information.
If you believe you have discovered a security vulnerability that affects aosu devices, software, services, or aosu-owned web servers, please report it to us. Anyone can submit a report, including security researchers, developers, and customers. We prioritize resolving security and privacy issues as quickly as possible.
Vulnerability Handling and Security Support
- Acknowledgment: Upon receiving a vulnerability report, aosu will acknowledge receipt within 10 business days and initiate the assessment process.
- Assessment & Status Updates: aosu will validate the reported issue and provide status updates to the reporter at least every 30 business days until a resolution or conclusion is reached.
- Remediation & Free Updates: During the applicable Security Support Period, aosu will handle confirmed vulnerabilities and provide appropriate security updates or other mitigation measures free of charge. Remediation timelines may vary depending on the severity and complexity of the vulnerability.
- Public Advisory: After a security update or other remediation is made available, aosu will provide relevant information to users, including the affected product models, versions, and clear instructions on how users can update or remediate the issue.
- Security Support Period: aosu provides vulnerability handling support and free security updates for at least 5 years from the official launch date of the product.
Conclusion
At aosu, we are committed to maintaining the highest standards of security and privacy for our users. Your contributions are invaluable in helping us achieve this goal. We appreciate your efforts in identifying and reporting vulnerabilities, and we are dedicated to working collaboratively to resolve any issues promptly and effectively. Together, we can create a safer and more secure environment for everyone. Thank you for being a part of the aosu Vulnerability Management Program.





































