Product Security Incident Report
ROBE acknowledges the requirements of the Cyber Resilience Act (CRA), based on Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024, and takes cybersecurity seriously across its products, services, and internal operations. This includes proactive prevention, as well as the identification and handling of cybersecurity incidents.
To support this commitment and meet regulatory requirements, ROBE operates a Product Security Incident Response Team (PSIRT) responsible for overseeing reported incidents and vulnerabilities, including intake, assesment, response coordination, and follow-up actions.
What should be reported?
The following cybersecurity vulnerabilities are considered in scope:
a) Unauthorized control of a device, including device control takeover via crafted packets.
b) Unencrypted or weakly encrypted communication, including authentication or encryption bypasses.
c) A vulnerability allowing execution of arbitrary code, including remote code execution via crafted packets.
d) A vulnerability allowing leakage of sensitive data.
e) Insecure update mechanism that could allow unauthorized or malicious updates.
f) Memory corruption or denial of service via crafted packets.
The following incidents are considered out of scope:
a) Physical access attacks
b) General best practice suggestions without a demonstrated attack path
How to report an incident?
a) Please report the security incident immediately using the form on this page. Information about the incident must not be disclosed, published, or shared elsewhere until the incident has been resolved.
b) When reporting a security incident, please include the following information:
Product details:
- Product name
- Serial number
- Last known software/firmware version installed on the device
Incident description
Please describe the incident in as much detail as possible and include supporting materials,
if available (e.g., screenshots or videos).
- When the incident occurred
- Where the incident occurred
- How the product was used or connected
- How the incident or threat manifested, e.g., loss of device control or data leakage
- What an attacker can do, including the potential impact and the conditions required
- A minimal reproduction case or proof-of-concept, if available
- Whether you believe the incident is remotely exploitable
c) Our PSIRT reviews all submitted reports. The associated risk is assessed, and, if required, the incident may be reported to the local CSIRT (cybersecurity incident response team) and to ENISA (the European Network and Information Security Agency).
You will be contacted within 24 hours with information about the next steps.
Thank you for your help in keeping us safe.