Skip to content

Security

Vulnerability Disclosure Policy (VDP) - RugGear

Vulnerability Disclosure Policy (VDP)

RugGear®

August 1, 2026  |  Version: 1.0

This policy complies with the mandatory requirements of the EU Cyber Resilience Act (CRA, EU 2024/2847) and is published in conjunction with the Coordinated Vulnerability Disclosure (CVD) management mechanism. It is addressed to all security researchers studying rugged industrial mobile hardware terminals, device firmware, and associated software.

1. Foreword

This policy establishes clear boundaries for security researchers conducting compliant security testing on RugGear rugged hardware devices and device firmware. It standardizes the full-process management rules for vulnerability reporting, coordinated remediation, and public disclosure, thereby implementing the mandatory requirements of the EU Cyber Resilience Act (CRA): a coordinated vulnerability disclosure mechanism, an independent vulnerability reporting channel, defined response timeframes, and device lifecycle security remediation guarantees.

This document explicitly defines the following:

  • The scope of rugged hardware terminals and firmware permitted for compliant testing;
  • Behavioral norms and prohibited actions for compliant security research;
  • Vulnerability report submission channels and material specifications;
  • Our vulnerability remediation grace period and coordinated public disclosure rules;
  • CRA statutory security incident reporting obligations (where actively exploited vulnerabilities exist, the 24/72/14-day EU ENISA reporting process must be followed).

We sincerely welcome security researchers, industry customers, and third-party security organizations to report any security vulnerabilities found in RugGear rugged devices and firmware.

2. Compliance Authorization Statement (CRA Safe Harbor Provision)

This clause constitutes a core element of CRA compliance. For researchers who act in good faith and conduct hardware/firmware security research in full compliance with this policy, we waive all civil and administrative claims, thereby establishing statutory safe harbor protection.

If you conduct security research on RugGear rugged mobile terminals and device firmware in good faith and in full compliance with all provisions of this policy, we consider your hardware reverse engineering and vulnerability testing activities to be formally authorized by RugGear. We will collaborate with you to expedite vulnerability verification and firmware patch development. For research activities that conform to this policy, RugGear will not initiate or assert any legal claims against you.

If a third party initiates legal proceedings against you for device security testing activities conducted in compliance with this policy, RugGear will issue this authorization statement as legal evidence on your behalf.

3. Compliant Research Behavior Standards (Adapted for Rugged Industrial Terminals and Firmware)

The term “compliant security research” as used in this policy refers solely to the following limited activities:

  • Upon discovering a real or potential security vulnerability in RugGear rugged terminals or firmware, submitting a complete report to us at the earliest opportunity;
  • Making every reasonable effort to avoid: voice call interception, device location data theft, communication service disruption, mass device offline events, tampering with terminal firmware parameters, or erasing device local storage data;
  • Using exploit techniques only to the minimum extent necessary to verify the existence of a vulnerability. Mass hijacking of online RugGear devices or implanting persistent backdoors is strictly prohibited;
  • Before publicly disclosing vulnerability details, proof-of-concept (PoC) scripts, or device exploit tools, allowing a reasonable remediation period for us to address the vulnerability;
  • Not submitting bulk reports of low-quality, duplicate vulnerabilities that pose no actual security risk.

Once you have successfully reproduced a terminal/firmware vulnerability or obtained any sensitive data during testing (e.g., push-to-talk recordings, device location information, terminal firmware keys, device configurations, third-party supplier proprietary code), you must immediately power off / disconnect the device from the network, cease all reverse engineering, packet capture, and debugging operations, and contact us without delay. Transmitting or exporting such sensitive data to any third party is strictly prohibited.

4. Prohibited Testing Methods (Rugged Industrial Device-Specific Prohibitions, CRA Risk Control Requirements)

The following testing activities are not authorized by us, constitute violations, and are not covered by the safe harbor protection of this policy:

  • Launching DoS/DDoS traffic attacks or stress testing against third-party OTA servers or carrier communication gateways, resulting in mass device offline events or communication service outages;
  • Physical destructive testing: forcibly disassembling terminals to read flash memory data, using hardware probes to extract firmware keys, damaging circuit boards, or tampering with customer-deployed devices. Social engineering attacks: spoofing RugGear official emails for phishing or stealing related credentials;
  • Large-scale scanning of online RugGear rugged mobile terminals, brute-forcing device access keys, or remotely flashing devices to tamper with official firmware;
  • Reverse engineering RugGear firmware and then publicly releasing unfixed firmware, encryption keys, or complete low-level device exploit tools without prior coordination.

5. Policy Scope (Adapted for Rugged Industrial Hardware Manufacturers, Meeting CRA Product Lifecycle Coverage Requirements)

The CRA requires that all hardware products and accompanying firmware with digital components placed on the EU market be covered by the VDP. This section uses a whitelist to enumerate all assets, distinguishing between proprietary assets and third-party vendor boundaries.

5.1  Preliminary Notes

  • Before any hardware or firmware is included in the testing scope, RugGear confirms that it holds complete testing authorization. Third-party chipset vendors’ closed-source firmware, third-party communication software, and carrier cellular base station networks are not within the scope of this policy. Vulnerabilities in these components should be reported directly to the respective suppliers.
  • Upon publication of this policy, all newly released RugGear rugged terminal models and new firmware versions are automatically included in the scope of this policy.
  • In accordance with the EU CRA, all RugGear digital rugged devices sold in the EU market are covered by this policy, with a minimum of 5 years of official security patch lifecycle support.

5.2  Assets Covered by This Policy (Whitelist)

  • RugGear full range of industrial rugged mobile devices: RugGear handheld broadband PoC radio terminals, in-vehicle communication devices, explosion-proof industrial rugged terminals, companion positioning accessories, and SOS emergency alarm modules;
  • Original device firmware: all officially released firmware versions, OTA upgrade packages, RugGear-customized bootloaders, built-in device OTA upgrade clients, firmware signature verification modules, hardware drivers, and terminal system customization components;
  • Device companion API interfaces, device local remote maintenance services, and device local data storage services.

5.3  Assets Not Covered by This Policy (Testing Prohibited)

  • Third-party chipset vendors’ closed-source firmware, third-party independently developed communication software, and carrier base station networks;
  • Third-party PTX/MCX push-to-talk applications and dispatch platforms used by EU-region customers (ownership and operation belong to communication carriers / third-party service providers; vulnerabilities should be reported directly to the respective service providers);
  • China-exclusive self-developed cloud dispatch platforms, PC dispatch clients, and China-dedicated radio applications (delivered exclusively for the Chinese market, not offered in the EU market, and not covered by this policy);
  • Third-party service provider-hosted OTA firmware distribution servers: our device firmware storage and distribution is provided by third-party cloud service providers. This cloud infrastructure is not a RugGear proprietary controlled asset. Scanning, penetration testing, or vulnerability testing of third-party OTA servers is prohibited. If vulnerabilities in third-party OTA platforms are discovered, please report them directly to the respective cloud service provider;
  • Customer on-premise private deployments and privately operated dispatch servers (separate written authorization from the customer must be obtained before conducting any testing);
  • Customized RugGear devices modified by distributors or third-party service providers;
  • Upstream native open-source framework code for bootloaders (e.g., original U-Boot), Android Open Source Project (AOSP), Google Mobile Services (GMS), Windows operating system and Microsoft native system components. These foundational software products are developed and maintained by third-party communities/vendors. Vulnerabilities in these native components should be reported to the respective providers.

If you are uncertain whether a particular terminal model, firmware version, or platform domain falls within the testing scope, please contact us via the security email security@ruggear.com for confirmation before initiating any reverse engineering, packet capture, or penetration testing.

Compliant security testing is permitted only against assets explicitly listed in this policy. If you discover a high-security-risk issue in a device or system not within scope, please contact us via email in advance. RugGear will continuously expand the coverage list of this policy.

6. Vulnerability Report Submission Standards (CRA Mandatory: Independent Reporting Channel, Anonymous Submission, Defined Response Timeframes, Incident Reporting Obligations)

The CRA mandates that manufacturers provide a continuously available vulnerability reporting channel, defined acknowledgment timeframes and a complete report material checklist. Furthermore, where actively exploited high-severity vulnerabilities exist, the statutory process requires a 24-hour early warning, submission of detailed materials within 72 hours, and a final report to EU ENISA within 14 days of patch release. This section incorporates all such compliance requirements in full.

All vulnerability information submitted through this policy is used solely for RugGear device security remediation and firmware patch development. If a vulnerability pertains to a common communication protocol or underlying chipset issue affecting the entire industry (not exclusively RugGear devices), we may forward the report to the EU ENISA coordinated vulnerability handling platform. Without the researcher’s written consent, RugGear will never disclose the researcher’s name or contact information to any third party.

6.1  Vulnerability Receiving Channels (Anonymous Reporting Supported, CRA Mandatory, Including PGP Encryption)

You may submit vulnerability reports through two secure channels, both of which support fully anonymous submission. RugGear does not require researchers to provide personal identity information:

  • Security receiving email: security@ruggear.com
  • RugGear PGP public key download URL: https://ruggear.com/security/pgp-key.asc
  • Public key fingerprint: 945D-8C31-04B4-1957-B98C-38E8-21B0-D6A7-786B-58F7
  • For vulnerabilities involving device firmware, hardware encryption keys, or mass device hijacking, please prioritize using PGP-encrypted email transmission, consistent with the ENISA coordinated vulnerability disclosure secure communication recommendation standard.

6.2  Recommended Report Materials (Specific to Industrial Rugged Hardware Devices)

To facilitate our rapid triage, device vulnerability risk assessment, and firmware patch development, reports should preferably include the following:

  • Complete affected product information: specific RugGear terminal model, firmware version, and affected functional modules (voice radio, positioning, OTA upgrade, SOS emergency alarm, local device configuration management);
  • Vulnerability impact description: potential risks (device hijacking, call interception, unauthorized firmware tampering, mass device offline events, local terminal positioning/radio recording data leakage, etc.);
  • Complete reproduction steps: hardware debugging operations, captured network packets, firmware reverse engineering procedures, PoC code, and vulnerability reproduction screenshots/videos;
  • Reports may be written in either Chinese or English. EU-based researchers are encouraged to use English to facilitate CRA compliance archiving.

6.3  Our Commitments to Researchers (CRA Coordinated Disclosure Mandatory Timeframes)

If you voluntarily provide contact information, RugGear commits to a fully transparent, coordinated resolution process:

  • Sending an acknowledgment receipt within 3 business days of receiving the report and assigning a dedicated vulnerability liaison;
  • Completing terminal/firmware vulnerability verification within 5 business days and communicating a preliminary risk rating (Critical / High / Medium / Low);
  • Clearly communicating the firmware patch release plan and sharing all technical blockers causing remediation delays;
  • Maintaining open communication channels throughout the process, providing updates on patch testing, security update rollout, and customer security notifications;
  • Upon vulnerability remediation completion, publishing a vulnerability advisory that meets CRA disclosure requirements, listing affected terminal models, fixed firmware versions, and temporary mitigation measures.

6.4  EU CRA Statutory Security Incident Reporting Obligations (Core Compliance Clause)

If we confirm the existence of a RugGear terminal/firmware critical vulnerability that is being actively exploited by malicious attackers, we strictly follow the ENISA unified reporting process:

TimeframeReporting ContentReporting RecipientCRA Legal Basis
Within 24 hours of becoming aware of active exploitationInitial early warning: vulnerability overview, affected product scope, potential impact assessmentENISA Single Reporting Platform + relevant national CSIRTArticle 14(1)
Within 72 hoursComplete vulnerability details, affected device model list, temporary mitigation measures, risk ratingENISA Single Reporting Platform + relevant national CSIRTArticle 14(2)
Within 14 days of security patch releaseComplete final disposition report: vulnerability root cause, remediation plan, patch deployment status, incident summaryENISA + CSIRTs of EU Member StatesArticle 14(4)

7. Coordinated Disclosure Timeline (CRA Standardized Coordinated Disclosure Cycle)

Our default remediation grace period is 90 days, calculated from the date on which we confirm the vulnerability as valid.

  • During the grace period, researchers shall not publicly disclose vulnerability details, firmware exploit PoCs, or terminal attack tools;
  • If the vulnerability risk is extremely high (e.g., capable of indiscriminate remote mass attack on terminals), both parties may negotiate a shortened grace period. If remediation cannot be completed within the scheduled timeframe due to complex technical issues, we will communicate proactively to negotiate an extension;
  • After the 90-day period concludes, researchers may publicly disclose vulnerability-related information. If we have already released a firmware fix, public disclosures should preferably include mitigation guidance and upgrade instructions.

8. Policy Revision Statement

  • RugGear reserves the right to continuously update this Vulnerability Disclosure Policy. Updated versions will be published on the official website security section. Upon publication of a new version, it supersedes all prior versions;
  • All vulnerability reporting activities are subject to the VDP version in effect on the date of reporting;
  • If you have any questions regarding this policy, please contact us at security@ruggear.com.

9. Device Security Lifecycle Statement

In accordance with the EU Cyber Resilience Act, we provide a minimum of 5 years of official security patch and vulnerability remediation support for all RugGear industrial rugged hardware products. The support period is calculated from the date of discontinuation of the corresponding terminal model. During the support period, we will develop free security firmware upgrade packages for all validly reported vulnerabilities. Terminals can obtain updates through the built-in OTA client. For older terminal models that have exceeded the security support period, we will publish risk advisories and offline security mitigation guidance on the product page in advance.

Document Revision History

VersionDateRevision DescriptionCompliance Basis
1.0August 1, 2026Initial policy release, adapted for RugGear industrial rugged radio hardware, meeting EU CRA baseline complianceEU CRA 2024/2847 Annex I Part II, Articles 5 & 6