01 / Scope
What do we handle?
This channel covers UNI-T electronic test and measurement products and the digital components required for their normal operation. Please provide the exact model, version and reproduction steps whenever possible.
Included in scope In scope
- Instrument firmware, bootloaders and embedded software.
- Official UNI-T PC software, drivers, configuration tools and SDKs.
- USB, LAN, Wi-Fi, Bluetooth and other communication interfaces and protocol implementations in products.
- Cloud services, APIs, remote control or online activation services required for normal product functions.
- Download, integrity-check, installation or upgrade mechanisms for firmware, software and security updates.
- Security flaws that can cause information disclosure, unauthorized access, code execution, denial of service or data tampering.
Outside this page Out of scope
- UNI-T marketing websites, CMS, corporate email, office networks and general enterprise IT infrastructure.
- Web content, accounts, orders, after-sales matters and general technical support issues unrelated to product security.
- Feature requests, measurement accuracy, hardware quality issues or product questions without a security impact.
- Vulnerabilities in third-party products or services; if they are integrated with a UNI-T product, please describe the impact path.
- Unauthorized destructive testing, social engineering, spam, denial of service or access to other people's data.
Scope boundary:General website or enterprise infrastructure issues are outside this page's public product scope. If a website, server or update distribution service is required for a product function or security update, explain that dependency in the report and we will escalate it internally based on its product security impact.
02 / Process
How do I submit a report?
You do not need to decide first whether an issue is an incident report under the CRA. Submit the facts and evidence; UNI-T will handle technical triage, product impact analysis and coordination.
Identify the product
State the product name, model, serial number if needed, firmware or software version, and the interface or connection method used.
State the reproduction
Provide the conditions, steps, minimal PoC, logs, screenshots or video needed to reproduce the issue. Avoid submitting real sensitive data.
Describe the impact
Describe the attacker's capabilities, affected assets, confidentiality, integrity and availability impact, and any signs of active exploitation.
Send the email
Send the report to security@uni-trend.com. English-language reports are welcome.
03 / Report
A strong report helps us fix issues faster
The template below is optional. The more complete the report, the faster we can identify the impact, confirm affected versions and plan a fix.
One channel, straight to the product security team.
We route incoming messages through product security triage. If we need to follow up, please include a reply address.
You may remain anonymous by omitting personal information, but anonymous reports may not receive follow-up status updates.
Suggested report template
Copy the fields below into the body of your email. Do not send passwords, private keys, customer personal information or unredacted production data.
Subject: Product Security Vulnerability Report — [Product / Model] Product / Model: Firmware / Software version: Hardware revision (if relevant): Interface / connection: Vulnerability summary: Reproduction steps: Proof of concept / evidence: Security impact: Known exploitation or disclosure status: Reporter contact (optional): Preferred language: Chinese / English
04 / Policy
Reporting rules and commitments
This page is based on coordinated disclosure. Our goal is to protect users while setting clear, trackable communication expectations for researchers, customers and UNI-T.
How will we respond?
We aim to acknowledge non-anonymous reports within five business days and provide initial feedback. For complex issues, we will explain the current status and next steps. Confirmed vulnerabilities enter internal assessment, remediation, validation and, where appropriate, a security advisory process. Timing depends on the impact, affected versions and remediation complexity.
Protect users and evidence first
Use the least-privileged, lowest-impact validation method possible. Do not read, modify or disclose other people's data, and do not conduct destructive testing or sustained denial-of-service activity. Give us reasonable time to confirm and remediate the issue. If it is being actively exploited, mark the subject line "ACTIVE EXPLOITATION".
How do we protect reporter information?
We use information you provide only as needed to process the report and will not disclose your identity without consent. Do not include personal information unrelated to the vulnerability, customer data, credentials or keys. For privacy matters, see UNI-T Privacy Policy.
Will the report be automatically sent to a CSIRT or ENISA?
No. security@uni-trend.com is UNI-T's product security intake mailbox; it does not replace an external CSIRT or CRA single reporting platform. We will assess active exploitation or serious incidents under applicable law, and the manufacturer will fulfill the required reporting obligations through the appropriate channels.
What about website, server and enterprise IT issues?
They are outside this page's public product reporting scope. Please use UNI-T contact page to report them. If you can show that the infrastructure is inseparable from a product function, remote service or security update mechanism, explain that in the report and we will move it into product security assessment.
05 / Advisories
Security advisories and updates
For confirmed vulnerabilities that affect product users, we may publish a security advisory, affected versions, mitigations and update information based on risk and remediation status.
Security advisories and remediation information
For confirmed vulnerabilities that affect product users, we may publish a security advisory, affected versions, mitigations and update information based on risk and remediation status. Please report the issue through security@uni-trend.com first. Visit the UNI-T Download Center for product firmware, software and driver updates.
Visit the Download Center ↗
