Report a Product Vulnerability or Security Issue

If you identify a vulnerability or a potential cybersecurity issue affecting a FAKRO product, please report it according to the instructions below. This applies in particular to products such as:

  • electronic devices;
  • controllers;
  • control units;
  • products using wireless communication;
  • mobile applications;
  • web applications used to operate products;
  • firmware and embedded software;
  • communication interfaces and services related to products.

Every report is reviewed by the FAKRO product security team.

How to Report a Security Incident?

Reports concerning a vulnerability or another cybersecurity issue affecting our product should be sent by email to: psirt@fakro.com

If you are sending confidential information or code demonstrating how a vulnerability can be exploited, you may encrypt your message using our PGP key.

Link to the key: PGP KEY

What Should the Report Include?

To allow us to verify the report efficiently, please provide the following information:

  • product serial number;
  • description of the issue you observed;
  • steps to reproduce the issue, if known;
  • information about the potential impact of the vulnerability;
  • your contact details (email address, phone number) so that we can contact you if necessary.

The serial number is the primary identifier of the product. It allows us to determine, among other things, the product model and the associated hardware and software versions. We also recommend attaching a photo of the product nameplate. This helps reduce the risk of the serial number being read incorrectly.

You may also attach additional materials that could help us analyse the issue, in particular:

  • photos or screenshots;
  • recordings;
  • system logs;
  • configuration files;
  • sample messages or network packets;
  • test reports;
  • a script or Proof of Concept demonstrating how to reproduce the vulnerability.

You do not need to prepare an exploit or classify the vulnerability yourself. It is sufficient to describe the issue you identified as accurately as possible.

What Happens After You Submit a Report?

After receiving your report, we will:

  1. confirm receipt of the report;
  2. verify whether the information provided is complete;
  3. carry out a technical analysis;
  4. contact you if necessary;
  5. determine the appropriate remediation measures and ways to mitigate the risk;
  6. inform you about the progress or outcome of the analysis, where possible.

Planned timeframe for acknowledging receipt of a report: up to 3 business days. The time required to complete the full analysis depends on the complexity of the issue, product availability, the need to perform tests and the scope of the required remediation measures.

Responsible Reporting Guidelines

When testing and reporting vulnerabilities, please follow these rules:

  • do not access other people's data;
  • do not copy, delete or modify data that does not belong to you;
  • do not disrupt the operation of products, services or infrastructure;
  • do not perform tests on customers' devices without their explicit consent;
  • do not exploit vulnerabilities for personal gain or to cause harm;
  • do not disclose vulnerability details publicly before a disclosure date has been agreed;
  • provide only the information necessary to carry out the analysis.

If, during testing, you accidentally gain access to personal data, confidential information or third-party systems, stop your activities immediately and describe the situation in your report.

Public Disclosure

Do not publish information that could enable exploitation of a vulnerability before the analysis has been completed and appropriate remediation measures have been implemented.

If a vulnerability is confirmed, we may agree with you on:

  • the publication date;
  • the scope of information to be disclosed;
  • how the person who submitted the report should be credited (your details will only be disclosed with your consent);
  • publication of a security advisory;
  • assignment of a CVE identifier, where appropriate.

Other Security Reports

If your report concerns the security of a website, IT infrastructure, user accounts or internal systems, please contact us via: cybersecurity@fakro.pl

Contact:

Product security team: FAKRO PSIRT
Email: psirt@fakro.com
PGP key: PGP KEY

Contact information for security.txt