End-to-End Vulnerability Handling Process
-
Report Intake
PSIRT registers incoming security reports and routes them internally according to established procedures.
-
Analysis & Validation
Relevant internal security teams assess the submission to determine whether it constitutes a confirmed security vulnerability.
-
Remediation
For confirmed vulnerabilities, we evaluate risk and product context and define an appropriate fix or mitigation plan.
-
Disclosure
After assessment and remediation planning, we determine the appropriate approach and timing for publishing security information.
-
Continuous Improvement
Through root-cause analysis, we strengthen best practices and continuously improve our overall product security capabilities.
Vulnerability Reporting Channels
If you identify a potential security vulnerability that may affect Quectel products, please contact Quectel PSIRT through the channel below.
Email:
psirt@quectel.comPlease include at least the following information in your email:
- Affected product model(s) and software/firmware version(s);
- Vulnerability type and a clear description;
- Steps to reproduce and/or exploitation method;
- Suggested remediation or mitigation;
- Any additional relevant details (e.g., logs, PoC, environment).
Secure Communication
Quectel PSIRT supports encrypted communications for the secure exchange of sensitive vulnerability information. When submitting a vulnerability report by email, we recommend encrypting sensitive content and attachments using the official Quectel PSIRT OpenPGP public key.
- Download Quectel PSIRT OpenPGP Public Key
- Key ID: ADE6B105FC37BD30 Fingerprint: 99B8 8CA6 ED45 FA3D 2EAC 7217 ADE6 B105 FC37 BD30
Reports submitted without OpenPGP encryption, including reports sent by unencrypted email, will still be accepted and processed.
* Note: Vulnerability details may be sensitive. We recommend encrypting attachments or files whenever possible.
Vulnerability Response & Disclosure Policy
Scope
This coordinated vulnerability disclosure policy applies to Quectel products, including modules, related software, and associated digital products and services. It is supported by, and operates in conjunction with, Quectel’s internal vulnerability handling policy and PSIRT process, which define the roles, responsibilities, and activities for handling reported vulnerabilities throughout their lifecycle.
Response Policy
Quectel PSIRT will provide an initial acknowledgement within one (1) business day after receiving your report, and will share a preliminary validation outcome within seven (7) business days.
Quectel PSIRT is committed to maintaining ongoing communication with reporters throughout the vulnerability handling process. While a confirmed vulnerability is being remediated, we will provide the reporter with a progress update at least every ten (10) business days, and will notify the reporter within twenty-four (24) hours after the corresponding fix or security update is released.
Disclosure Policy
Quectel PSIRT evaluates factors such as a vulnerability’s impact and exploitability, and once an appropriate remediation plan is confirmed, publicly discloses the vulnerability details and corresponding remediation through the security advisories.
Where applicable, a published security advisory will at least include: the CVE identifier, CWE classification, CVSS severity rating, affected products and versions, a description of the vulnerability and its impact, and the remediation measures or fixed version information.
Coordinated Disclosure & Embargo
To protect users, Quectel will not publicly disclose vulnerability details to any third party before an official fix or security update is made available. Where mutually agreed, Quectel and the vulnerability reporter may jointly define a coordinated disclosure timeline. We likewise request that reporters keep vulnerability information confidential until a remediation has been made available.
Recognition
Quectel values the contributions of security researchers and reporters. With the reporter’s consent, Quectel may acknowledge the reporter in the corresponding security advisory.
Referenced Standards
Throughout the vulnerability handling lifecycle, Quectel PSIRT follows widely adopted standards and industry best practices, including but not limited to:
- CVSS (Common Vulnerability Scoring System)
- FIRST (Forum of Incident Response and Security Teams)
- ISO/IEC 29147 (Vulnerability Disclosure)
- ISO/IEC 30111 (Vulnerability Handling Processes)
* Note: Timelines may vary depending on vulnerability severity, verification complexity, and impact scope, among other factors.
Security Statement
Important Notice
Quectel recognizes and supports good-faith security research and necessary technical validation performed in controlled environments. All related activities must comply with applicable laws and regulations and must not impact production environments or third-party rights. The following activities are not considered acceptable forms of security research:
- Conducting destructive testing, exploitation, or any other unauthorized activities in production environments involving IoT modules, associated devices, or platforms that may disrupt normal operations.
- Illegally obtaining, reproducing, or disseminating IoT module firmware or related sensitive information through unauthorized reverse engineering or other improper means, thereby infringing upon the intellectual property rights of Quectel.
- Illegally intercepting, monitoring, altering, or tampering with module communication data, or accessing, acquiring, or disclosing sensitive data of users or third parties, thereby compromising data security and privacy.
- Exploiting vulnerabilities in modules to attack associated devices, infiltrate networks, or otherwise compromise network security and public interests.
- Circumventing regulatory requirements or engaging in any other activities that violate applicable laws and regulations or infringe upon the legitimate rights and interests of our company or third parties.
* Note: Final interpretation of the information on this website belongs to Quectel.