Contact
Contact
RAFI GmbH & Co. KG

Ravensburger Str. 128–134
88276 Berg/Ravensburg
Germany
P +49 751 89-0
F +49 751 89-1300

Phone Link
  1. Home
  2. Ι Company
  3. Ι Business
  4. Ι CVD Policy
CVD Policy

Reporting Vulnerabilities

The security of our products is important to us. If you have discovered a vulnerability in a RAFI product, please report it to us before disclosing it publicly.

Contact

We maintain two separate functional mailboxes, please select the appropriate one:

Vulnerability in a RAFI product

(firmware, software, device)

Get in touch
Vulnerability in RAFI infrastructure

(website, web services, corporate IT)

Get in touch

What We Need from You

  • Affected product, hardware version, and firmware/software version
  • Description of the vulnerability and its potential impact
  • Reproducible steps to recreate the issue
  • Your contact details for follow-up questions
     

We ask that you do not publicly disclose suspected vulnerabilities without prior consent from RAFI.

If we cannot confirm a vulnerability, we will provide you with our assessment and rationale, and offer a direct discussion in case of differing evaluations.

Commitment to Reporters (Safe Harbor)

If you act in good faith, adhere to this policy, and:

  • Do not access, modify, or publish third-party data
  • Do not disrupt or degrade the operation of systems and facilities
  • Do not conduct social engineering, phishing, or denial-of-service (DoS) attacks
  • Treat your findings confidentially until a coordinated disclosure is agreed upon
     

RAFI will not take legal action against you and will treat your report as a valuable contribution to product security.

Out of Scope

  • IT systems and web services of RAFI corporate IT, please direct to security@remove-this.rafi-group.com
  • Products outside their supported lifecycle (End of Support / EOL)
  • Vulnerabilities resulting exclusively from improper use or operation outside intended specifications

Disclosure & Publication

Following the deployment of a remediation measure, we publish a Security Advisory detailing the issue, affected versions, severity rating, and recommended actions. In justified cases, publication may be deferred to allow users sufficient time to apply the update.

site-to-top