Security Vulnerability Disclosure Policy
This Security Vulnerability Disclosure Policy describes how security researchers, customers and other third parties can report suspected security vulnerabilities affecting Mondo Robotics products.
Vulnerability Response
Safeguarding against security issues is a top priority for us and we welcome anyone with a security background to report potential security vulnerabilities to us to improve the security of our products and services.
Scope
This policy applies to Mondo Robotics consumer connectable products, including hardware, firmware, software and associated services.
Examples of security issues that may be reported include: - Authentication or access control weaknesses; - Firmware or software vulnerabilities; - Encryption or data protection weaknesses; - Remote access or network security vulnerabilities.
This policy does not cover: spam; social engineering; physical attacks; and vulnerabilities requiring outdated third-party software.
Vulnerability Response and Disclosure Process
1. Receive and acknowledge
Monitor and promptly assign confirm the receipt of received reported vulnerabilities
2. Verify
Verify whether the vulnerability is reproducible and confirm the exploitability and impact
3. Develop Solution
Provide effective solutions or risk remediation measures
4. Confirm Scope
Investigate and confirm the scope of affected products
5. Release Security Advisory
Review and publish the security advisory (SA) for the vulnerability
Report Vulnerabilities
Please report any security vulnerabilities via email to: support@mondorobotics.com
The email should include at least the following information, ideally as an attachment in this format:
- Your organization and contact information (non-mandatory)
- Products and versions affected
- Description of potential vulnerability
- Information about known exploits
- Disclosure plans
Important Note
Although we encourage the investigation of potential security breaches, we cannot tolerate any activity that may interfere with legitimate users or violate applicable computer abuse, cyber security and data protection regulations. Therefore, the following activities are prohibited:
- Modification or destruction of data
- Service disruption or degradation, such as DoS
- Disclosure of personal, proprietary or financial information
- Accessing data beyond what is necessary to demonstrate the vulnerability
- Installing malware
- Attempting social engineering
- Physical attacks against the devices
- Automated high-volume scanning
Response Time
After you have submitted your report, we will respond to your report within 5 working days and aim to triage your report within 10 working days. We will also aim to keep you informed of our progress.
(Actual vulnerability response time may vary depending on the risk level and complexity of the vulnerability)
Vulnerability Disclosure Instructions
When an external party discovers or is concerned about a potential vulnerability, but we have not yet fully confirmed it, we will disclose basic information about the vulnerability and our investigation via email.
The vulnerability information shall be kept confidential until Mondo Robotics releases the formal security advisory to the public. Mondo Robotics will coordinate disclosure timelines with the reporter where appropriate. Public disclosure should generally occur after remediation measures are available or after reasonable efforts have been made to mitigate the risk.
When the vulnerability has been confirmed to be fixed, new firmware will be released, and a firmware update change log will be published, containing a description of the vulnerabilities that have been solved.
Product Support Policy
We strive to provide continuous security updates for our products. The security updates generally include the latest patches, vulnerability fixes, and other security improvements. We will generally maintain security updates for at least two years from the launch date of a product. However, the security update situation may vary by product, so please pay attention to our announcements. We will regularly publish and update information about the security of Mondo Robotics products on this page to help you check your device’s security updates.
|
Product Type
|
Product Name
|
Model
|
Release Date
|
End Date
|
|
Wheel-legged robot
|
Beni
|
LZA5211
|
2026/7/8
|
2028/12/31
|
Note: Security update policies and products are subject to change and will be reviewed on a regular basis.