CRA Vulnerability Report
We are always committed to ensuring the security of our products and solutions, and sincerely invite partners from all walks of life to join us in collaborative defense.
Vulnerability Response and Disclosure Process
Receipt
Receive and collect vulnerability reports, contact and confirm with the reporters of the vulnerabilities.
Verification
Confirm the reported vulnerabilities truly exist and accurately identify the actual risks.
Remediation Development
Formulate scientific and implementable repair strategies to ensure the system returns to a safe state.
Release
Notify progress and close the loop in communication.
Vulnerability Advisory
Transparent disclosure, release security recommendations.
Vulnerability Submission
If you identify any potential safety risks or vulnerabilities related to the product, please inform us promptly via email at: support@thermalmaster.com
Thank you for your efforts in jointly maintaining the product's security ecosystem.
Note: To ensure that the vulnerability information you submit can be effectively evaluated and handled, please include the following key information in the email:
- Your name and contact details.
- The specific product name, model, and firmware/software version number that is affected.
- The detailed description of the vulnerability, including its type and potential impact.
- The triggering conditions or verification steps for the vulnerability.
- Any supplementary materials that can help us verify and solve the problem.
Vulnerability Response
After receiving the vulnerability you submitted, we will send you a notification of vulnerability response activation via email within 48 hours, along with information confirmation and feedback regarding the vulnerability. The progress of the vulnerability repair will also be updated in the email notification as soon as possible.
Note: The actual response time for vulnerabilities may vary depending on the risk level of the vulnerability and the complexity of the situation.
Disclosure and Advisory
Issue the security vulnerability advisory for the product via the following link.
Note: Before the official security advice is released, the vulnerability submitter must keep the details of the vulnerability confidential.


