This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Cookie Policy.
>
Security

Vulnerability Disclosure Policy

UNI-T welcomes reports of potential security vulnerabilities in our products, firmware, software, and websites. This page explains how to submit a report and how we handle it.

This page is only for reporting UNI-T product security vulnerabilities. It is not an incident channel for the corporate website, servers, enterprise network or general technical support. For those issues, please visit Contact UNI-T.

01 / Scope

What do we handle?

This channel covers UNI-T electronic test and measurement products and the digital components required for their normal operation. Please provide the exact model, version and reproduction steps whenever possible.

Included in scope In scope

  • Instrument firmware, bootloaders and embedded software.
  • Official UNI-T PC software, drivers, configuration tools and SDKs.
  • USB, LAN, Wi-Fi, Bluetooth and other communication interfaces and protocol implementations in products.
  • Cloud services, APIs, remote control or online activation services required for normal product functions.
  • Download, integrity-check, installation or upgrade mechanisms for firmware, software and security updates.
  • Security flaws that can cause information disclosure, unauthorized access, code execution, denial of service or data tampering.

Outside this page Out of scope

  • UNI-T marketing websites, CMS, corporate email, office networks and general enterprise IT infrastructure.
  • Web content, accounts, orders, after-sales matters and general technical support issues unrelated to product security.
  • Feature requests, measurement accuracy, hardware quality issues or product questions without a security impact.
  • Vulnerabilities in third-party products or services; if they are integrated with a UNI-T product, please describe the impact path.
  • Unauthorized destructive testing, social engineering, spam, denial of service or access to other people's data.

Scope boundary:General website or enterprise infrastructure issues are outside this page's public product scope. If a website, server or update distribution service is required for a product function or security update, explain that dependency in the report and we will escalate it internally based on its product security impact.

02 / Process

How do I submit a report?

You do not need to decide first whether an issue is an incident report under the CRA. Submit the facts and evidence; UNI-T will handle technical triage, product impact analysis and coordination.

STEP 01

Identify the product

State the product name, model, serial number if needed, firmware or software version, and the interface or connection method used.

STEP 02

State the reproduction

Provide the conditions, steps, minimal PoC, logs, screenshots or video needed to reproduce the issue. Avoid submitting real sensitive data.

STEP 03

Describe the impact

Describe the attacker's capabilities, affected assets, confidentiality, integrity and availability impact, and any signs of active exploitation.

STEP 04

Send the email

Send the report to security@uni-trend.com. English-language reports are welcome.

03 / Report

A strong report helps us fix issues faster

The template below is optional. The more complete the report, the faster we can identify the impact, confirm affected versions and plan a fix.

Report by email

One channel, straight to the product security team.

We route incoming messages through product security triage. If we need to follow up, please include a reply address.

Email security@uni-trend.com

You may remain anonymous by omitting personal information, but anonymous reports may not receive follow-up status updates.

Suggested report template

Copy the fields below into the body of your email. Do not send passwords, private keys, customer personal information or unredacted production data.

Subject: Product Security Vulnerability Report — [Product / Model]
Product / Model:
Firmware / Software version:
Hardware revision (if relevant):
Interface / connection:
Vulnerability summary:
Reproduction steps:
Proof of concept / evidence:
Security impact:
Known exploitation or disclosure status:
Reporter contact (optional):
Preferred language: Chinese / English

04 / Policy

Reporting rules and commitments

This page is based on coordinated disclosure. Our goal is to protect users while setting clear, trackable communication expectations for researchers, customers and UNI-T.

How will we respond?

We aim to acknowledge non-anonymous reports within five business days and provide initial feedback. For complex issues, we will explain the current status and next steps. Confirmed vulnerabilities enter internal assessment, remediation, validation and, where appropriate, a security advisory process. Timing depends on the impact, affected versions and remediation complexity.

Protect users and evidence first

Use the least-privileged, lowest-impact validation method possible. Do not read, modify or disclose other people's data, and do not conduct destructive testing or sustained denial-of-service activity. Give us reasonable time to confirm and remediate the issue. If it is being actively exploited, mark the subject line "ACTIVE EXPLOITATION".

How do we protect reporter information?

We use information you provide only as needed to process the report and will not disclose your identity without consent. Do not include personal information unrelated to the vulnerability, customer data, credentials or keys. For privacy matters, see UNI-T Privacy Policy.

Will the report be automatically sent to a CSIRT or ENISA?

No. security@uni-trend.com is UNI-T's product security intake mailbox; it does not replace an external CSIRT or CRA single reporting platform. We will assess active exploitation or serious incidents under applicable law, and the manufacturer will fulfill the required reporting obligations through the appropriate channels.

What about website, server and enterprise IT issues?

They are outside this page's public product reporting scope. Please use UNI-T contact page to report them. If you can show that the infrastructure is inseparable from a product function, remote service or security update mechanism, explain that in the report and we will move it into product security assessment.

05 / Advisories

Security advisories and updates

For confirmed vulnerabilities that affect product users, we may publish a security advisory, affected versions, mitigations and update information based on risk and remediation status.

Security advisories and remediation information

For confirmed vulnerabilities that affect product users, we may publish a security advisory, affected versions, mitigations and update information based on risk and remediation status. Please report the issue through security@uni-trend.com first. Visit the UNI-T Download Center for product firmware, software and driver updates.

Product support information Support periods, available updates and version information for a specific product are governed by its product page, user manual and official downloads.

Visit the Download Center ↗