Report a Vulnerability

Please report suspected vulnerabilities in Portwell products, supported firmware or software, Portwell-operated services, or official websites through our official channels below.

Reporting Channels

To make submission as easy as possible, we offer two reporting methods:

If your report includes highly sensitive supporting evidence (such as detailed logs or PoC test code), we strongly recommend using PGP encryption via email.

Information to Include

Include the following information where available. This guide does not limit the submission of other information that may help Portwell assess the report.

  1. Reporter contact information: name, organization, and email address.
  2. Affected product: product name, model, hardware revision, and firmware or software version.
  3. Technical description: expected and actual behavior, known or potential impact, and affected security properties.
  4. Reproduction steps: required equipment, software, configuration, network environment, and sequence of actions where applicable.
  5. Supporting evidence: proof-of-concept material, screenshots, logs, packet captures, non-malicious test code, or other evidence.
  6. Potential exploitation: how an attacker could exploit the issue, prerequisites, and potential attack path.
  7. Additional context: any information that may clarify scope, impact, or remediation options.

Safe and Responsible Reporting

Use only accounts, devices, and data that you own or are authorized to use. Minimize impact, stop testing if personal, confidential, credential, or customer data is encountered, and keep non-public findings confidential until coordinated disclosure.

※ Please do not include passwords, credentials, unnecessary personal data, customer data, or destructive test material in your report.

You can submit your findings directly using our secure online form. Please review the  [ Information to Include ]  section below to ensure you have all the necessary details ready for efficient validation and investigation.

[CVD] PSIRT Vulnerability Reporting Form

1. Reporter Information

Please provide your contact details so we can reach out for clarification.

2. Affected Product Details

Identify the specific product and version affected by the vulnerability.

3. Vulnerability Technical Details

Provide in-depth technical details about the discovered vulnerability.