Vulnerability Response Process

Hoymiles Product Vulnerability Handling System

1.Purpose

Hoymiles maintains a vulnerability management system covering policy, organization, process, governance, and technology. This policy applies to all security vulnerabilities you intend to report. Please read it in full before submitting a report and follow it throughout the process.

2.Scope of Products Covered

This policy applies to all products with digital elements developed or maintained by Hoymiles Power Electronics Inc., including but not limited to:

PV Inverters, DTUs, Rapid Shutdown Devices ,Transmitters, Power Convertor Systems and Electrochemical Battery Energy Storage Systems and etc.


3.Vulnerability-Handling Process

image.png

  1. Vulnerability Awareness: Receive suspected vulnerabilities reported by various parties and create vulnerability-tracking work orders.

  2. Verification and Assessment: Verify the authenticity of vulnerabilities, assess their severity levels and affected scope, determine remediation priorities, and formulate temporary mitigation measures.

  3. Vulnerability Remediation: Develop and test patches or new software versions.

  4. Remediation Information Release: Issue security advisory to inform the public of risks and corresponding disposal solutions.

  5. Closed-Loop Improvement: Conduct post-incident reviews, integrate security learnings into product R&D workflows to achieve continuous security optimization.

4.Vulnerability Reporting

Please enter this page's official form through the following redirection port to report the security vulnerabilities . 

Reporting Suspected Vulnerabilities.

Please do not trust any other links, email addresses, or third-party pages.

We accept anonymous vulnerability reports. However, please note that without contact information, we will be unable to provide updates on the handling progress or offer acknowledgments.

We welcome security researchers, industry organizations, customers and suppliers to report suspected vulnerabilities to Hoymiles PSIRT (Product Security Incident Response Team). We require upstream suppliers to timely feedback vulnerabilities found in their deliverables, and conduct impact assessments for products within the securitysupport period. Hoymiles recommends customers periodically check product support status to ensure access to software updates.

5.Vulnerability Confidentiality and Coordinated Disclosure

To protect our users, we request that you refrain from publicly disclosing the vulnerability until we provide fixes or mitigation measures.

We follow the coordinated disclosure principle:

  • Privately notify reporters upon fix availability.

  • Publish security bulletin after users have had reasonable time to apply the fix.

  • Public disclosure will normally occur after the appropriate remediation or mitigation is available. The disclosure timing may be reviewed and adjusted where active exploitation is identified, vulnerability information becomes public, risk materially changes, remediation is delayed or becomes available earlier, or applicable legal or regulatory requirements require earlier action.

Security advisory will be published through the company’s designated public security advisory or product support webpage. Where appropriate, affected customers, users, integrators or partners may also be notified through approved customer support, email, portal or other direct communication channels.

Available security updates, corrected versions, patches or mitigation instructions will be distributed through the applicable product update service, product support or download portal, customer support channel, or another approved secure distribution channel. The advisory will identify the affected products and versions, available remediation or mitigation, required user actions and applicable support contact.

Meanwhile, we duly protect the received data in compliance with applicable legal requirements and will not disclose relevant data to external parties unless required by applicable law or permitted by the affected customers.

6.Vulnerability Severity Assessment Criteria

Hostiles assesses the severity of suspected product vulnerabilities based on industry standards and the scope of vulnerability impact. Taking the CVSS score as the baseline metric, we evaluate the hazard level of vulnerabilities in combination with usage scenarios of the attacked products and vulnerability impact scope.

We adopt the Security Severity Rating (SSR) as our vulnerabilityclassification methodology. Via SSR, vulnerabilities can be categorized into Critical, High, Medium, Low based on the overall severity score.

7.Our Commitment

Upon full remediation of the vulnerability, we will disclose the vulnerability and relevant handling outcomes in the security advisory.

Response Commitments:

  • Acknowledgement: Confirm receipt within 3 working days. 

  • Verification: Investigate and validate the vulnerability. 

  • Remediation: Develop and test appropriate fixes or mitigation measures based on assessed risks. 

  • Notification: Timely inform you of progress updates.

  • Disclosure: After a remediation solution becomes available, a security advisory may be issued depending on the specific circumstances and risk assessment.

  • Acknowledgment of Contribution: Recognize your contribution in the security advisory (unless you prefer to remain anonymous).

8.Confidentiality and Secure Information Sharing

Non-public vulnerability information will be shared only where necessary for vulnerability verification, remediation, mitigation, protection of affected users, coordination with relevant suppliers or maintainers, coordinated disclosure, or compliance with applicable legal and regulatory obligations.

Information will be limited to what the recipient needs for the relevant purpose and shared through an appropriate controlled channel. Where appropriate, the recipient will be informed of applicable confidentiality requirements. Personal information of the reporter will not be shared without consent unless required by law. For more information about how Hoymiles handles your personal data, please visit our  [Privacy Policy].

9.Testing Scope, Prohibited Activities and Safe Harbor

The following activities are outside the scope of this policy:

  • Exploiting vulnerabilities using high-intensity intrusive and destructive scanning tools 

  • Conducting or reporting any form of denial-of-service attacks, such as overwhelming services by sending massive requests 

  • Unauthorized public disclosure of vulnerabilities before both parties explicitly agree on the disclosure timeline

  • Denial-of-service testing against production systems 

  • Social-engineering attempts

We authorize good-faith, non-malicious security testing of products and systems within the scope of this policy, provided that the testing complies with this policy, and applicable law. Testing shall avoid harm to users, disruption of services, unauthorized access to or modification of data, privacy violations, and access beyond what is necessary to demonstrate the vulnerability.

Where testing is conducted in accordance with this policy, we will consider the activity authorized for the purpose of vulnerability research and will not initiate legal action solely based on that activity. This authorization does not apply to testing outside the defined scope or to activities prohibited by this policy.

10.Policy Review

This policy shall undergo an internal review annually or following major security incidents. The latest version of this policy is available on our Company's official website.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. For more details about cookies and how to manage them see our Privacy Policy.