DOBOT takes the cybersecurity of its products and services seriously. We welcome security researchers, customers, and partners to report potential security vulnerabilities identified in DOBOT products, software, firmware, or related services.
View the complete Coordinated Vulnerability Disclosure (CVD) Policy
| Channel | Contact Details | Description |
|---|---|---|
| Security Email | support@dobot-robots.com | Please use encryption when appropriate. |
| After-sales Hotline | 400-800-7266 | This hotline accepts initial vulnerability reports only. Detailed technical information must be submitted through the security email address or online form. |
To help the Project and Quality Operations Center efficiently triage, reproduce, and assess the risk of a reported vulnerability, external reporters should provide as much of the following information as possible when submitting a report through one of the channels listed in Section 1: reporter details (name or alias and contact information); affected product, model, and firmware version; vulnerability type and affected component; detailed reproduction steps or proof of concept (PoC); estimated scope and severity of impact; known temporary mitigations; whether the vulnerability has already been publicly disclosed or submitted to another vulnerability database; and disclosure preferences, including whether the reporter wishes to remain anonymous and the preferred timing and method of disclosure. Complete reports enable a faster response and more effective coordination.
At a minimum, a vulnerability report should address the following elements:
External parties may report product security vulnerabilities to DOBOT through the security email address published on the official website or through the after-sales support team for referral.
Vulnerability reports may be submitted by email. If encrypted transmission is required, reporters may contact the security email address to obtain the appropriate encryption method. Sensitive information containing vulnerability details will be handled only by the Project and Quality Operations Center and other authorized response personnel within a controlled internal environment and must not be disclosed externally.
The Project and Quality Operations Center will accept and log vulnerability reports submitted through unencrypted channels, such as standard email or telephone, and will not reject a report solely because the communication channel is not secure. After receipt, the reporter will be guided to use a secure communication method, such as encrypted email, for subsequent exchanges. Appropriate safeguards will be applied to sensitive information already received during internal handling.
Under normal circumstances, the Project and Quality Operations Center will acknowledge receipt within two business days, complete initial triage within five business days, and provide the reporter with regular progress updates during remediation, with no more than 15 calendar days between updates. The reporter will be notified when remediation is complete and the report is closed. If these timeframes cannot be met because of analytical complexity or the need for internal coordination, DOBOT will explain the circumstances to the reporter. If the report does not contain sufficient information to support a risk assessment or reproduction of the vulnerability, DOBOT will request additional information.
A request for additional information will identify the specific missing or required information, such as the product model and firmware version, triggering conditions, complete reproduction steps, log files, or environment configuration; explain why the information is needed; and specify a recommended response timeframe.
If a report is submitted through an unencrypted channel, the reporter will be guided during the initial contact to use a secure communication method, such as PGP-encrypted email, for subsequent exchanges. Communications involving sensitive information, including vulnerability details, reproduction code, or network topology, must take place through a secure channel.
If the reporter does not respond within the requested timeframe, the Project and Quality Operations Center will send at least one follow-up reminder. If the reporter still does not respond after the reminder or declines to use a secure channel, the Project and Quality Operations Center may assess the risk based on the available information and will record the communication attempts in the vulnerability record.
Once a remediation is available, DOBOT may issue a security advisory or customer notification. The advisory may include a description of the vulnerability, potential impact, identifier, affected versions, severity, remediation instructions, publication date, update date, and acknowledgment of the reporter with the reporter's consent.
Following internal assessment and management approval, vulnerability information may be published in the European Vulnerability Database (EUVD). Publication will be coordinated by the Project and Quality Operations Center and reviewed by the Legal and Compliance Department.
Public disclosure of vulnerability information may be delayed to allow time for security updates to be distributed, provided that all of the following conditions are met:
Once all conditions are met, the Project and Quality Operations Center will document the reasons for delayed disclosure and the relevant authorization and approval, and will notify the reporter of the delayed disclosure arrangement.
With the reporter's consent, DOBOT may publicly acknowledge the reporter in a security advisory or on an acknowledgment page. Reporters may choose to remain anonymous.
If you discover a potential security vulnerability or security incident involving a DOBOT product, software, firmware, or related service, please send the relevant information to our security contact email:
support@dobot-robots.com | After-Sales Hotline: 400-800-7266
We recommend using the following email subject line:
Security Vulnerability Report – [Product Name/Model]
To help us promptly log, analyze, and validate the issue, please provide the following information:
Please fill in the form below. Your report will be sent directly to our security team. We will acknowledge receipt within 3 business days.
*Submission of Sensitive Information
If your report contains non-public vulnerability details, exploit code, customer data, or other sensitive information, please contact us at the email address above before submitting such materials. We will provide an appropriate encrypted or secure transmission method.
We will apply appropriate confidentiality and access controls to non-public vulnerability information, exploitation details, customer data, and other sensitive materials received.
The information you submit will be used only to receive, analyze, validate, and address security vulnerabilities and to comply with applicable legal obligations.
For further information about how DOBOT processes personal information, please refer to the DOBOT Privacy Policy.
Take part in automation transformation. Let’s work together towards a more efficient tomorrow.