Vulnerability Disclosure Policy

At CSS Electronics we take the security of our products seriously - see e.g. our CANedge/CANsub security articles. This policy explains how to report a potential security vulnerability in any of our products or our website - and what you can expect from us in return.


How to report

If you believe you have found a security vulnerability, please email us at contact@csselectronics.com. This inbox is monitored directly by our engineering team. Please include where possible:

  • The product and firmware/software version affected
  • A description of the issue and its potential impact
  • Steps to reproduce (proof-of-concept, configuration, network setup)
  • Your contact details for follow-up questions

What you can expect from us

  • We acknowledge your report within 3 business days
  • We assess the issue for exploitability and impact, and keep you informed of our progress
  • Our team will seek to resolve issues as fast as possible via free, digitally signed firmware/software updates
  • Once a fix is available, we publish information about this via our firmware changelog

Coordinated disclosure

We ask that you give us a reasonable opportunity to remediate the issue before any public disclosure - as a guideline, 90 days from your report. We may ask to coordinate the disclosure timing where a fix requires roll-out time across affected users. Where relevant, we handle regulatory notifications (e.g. under the EU Cyber Resilience Act) as part of the same process.


Safe harbour

We will not pursue legal action against security research conducted in good faith that follows this policy. When testing, please do not access, modify or delete data that is not yours, do not degrade our services or those of our users, and only test against devices and accounts you own or have permission to use.


The following are outside the scope of this policy:

  • Denial-of-service testing against our website or hosted services
  • Social engineering, phishing or physical attacks against CSS Electronics staff or facilities
  • Reports concerning the absence of security controls on devices deployed by third parties (e.g. a CANsub deployed without mTLS enabled), where the product documentation directs users to enable them
  • Vulnerabilities in third-party platforms we use but do not operate (please report these to the respective vendor)

Reported vulnerabilities are analyzed for exploitability, risk impact and required mitigation. Confirmed issues are remediated through digitally signed firmware updates or configuration guidance, announced via our official changelogs and documentation portal. Where legally required, we additionally notify the relevant authorities (e.g. ENISA and the national CSIRT under the EU Cyber Resilience Act) and inform impacted users.



Questions about this policy or our product security?

Contact us