1. Our Commitment

Comba attaches high importance to product cybersecurity. We welcome and thank global security researchers for responsibly disclosing security risks and product vulnerabilities to us.

We commit to:

  • Provide safe harbor protection for security researchers who conduct good-faith, responsible Security Risk disclosure in compliance with this Policy.
  • Respond to all reports of Security Risk in a timely manner and maintain transparent communication.
  • Rapidly verify and remediate Security Risk, and release security updates to users.
  • Publicly acknowledge contributors in official security advisories upon the reporter’s consent.

 


 

2. Scope of Application

This Policy applies to external security researchers, partners, and users who report security risks affecting Comba products available on the EU market, including hardware, firmware, and remote network management systems.

 

Exclusions

This Policy does not apply to:

  • Security Risk already publicly disclosed by third parties;
  • Native Security Risk inherent to third-party and/or open-source components. Please report such issues directly to the original component vendors; or
  • Non-product code Security Risk such as social engineering attacks, physical sabotage attacks, and distributed denial-of-service (DDoS) attacks.

 

2.1 Severe Security Incidents

As defined in Article 14(5) of the EU Cyber Resilience Act (CRA), a severe incident having impact on the security of a product (“Severe Security Incident”) can be based on either of the following:

  • It negatively affects, or is capable of negatively affecting, the product’s ability to protect the availability, authenticity, integrity, or confidentiality of sensitive or important data or functions; or
  • It has led to, or is capable of leading to, the introduction or execution of malicious code in the product or in a user’s network and information systems.

 

2.2 Special Instructions on Third-Party Component Vulnerabilities

The complete list of all third-party software components adopted by our products is available in the official released SBOM file in SPDX 2.3 format corresponding to each product version.

For native vulnerabilities of third-party components:

  • We will continuously track security advisories and patch releases issued by upstream communities.
  • For component vulnerabilities that jeopardize product security, we will release security firmware containing component upgrades within 15 working days after risk assessment.
  • We will clearly mark remediated third-party component vulnerabilities and their corresponding CVE IDs in official security advisories.
  • If you discover undisclosed vulnerabilities in third-party components integrated into our products, you may submit reports via the channels specified in this Policy, and we will forward your findings to the original component vendors accordingly.

 


 

3. Official Vulnerability Reporting Channels

Comba provides the following official Security Risk reporting channels.

 

Encrypted Email

Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

These channels can be used for all vulnerability reports and are the preferred channels for reporting sensitive vulnerabilities.

 

Dedicated Hotline

Phone: +34 910 618 108

Availability: Monday to Friday, 9:00-18:00 (Madrid time)

The hotline is intended for immediate reporting of critical high-risk vulnerabilities and vulnerabilities under active exploitation.

 

Hardcopy Mail

Address: Calle Diego de León 69, esc. 1, 2A, 28006 Madrid

Purpose: Submission of formal written vulnerability reports and paper supporting materials.

 


 

4. Security Risk Report Requirements

To support efficient Security Risk verification and remediation, please include as much of the following information as possible in your submission:

  1. Security Risk name, CWE ID (if available), and CVE ID (if available).
  2. Exact model numbers and firmware versions of affected products.
  3. Detailed, reproducible Security Risk exploitation steps.
  4. POC code or demonstration video, if available.
  5. Security Risk impact scope and potential risk assessment.
  6. Your contact information, if you would like to receive follow-up information regarding remediation progress.

 


 

5. Secure Communication Specifications

5.1 Encrypted Communications

For reports containing highly sensitive information, such as confidential Security Risk exploit codes and user data leakage, we strongly recommend communication via email.

 

5.2 Anonymous Reporting

Anonymous Security Risk reports are accepted.

If you choose to remain anonymous, we will not trace your identity. However, we may be unable to provide you with progress updates regarding Security Risk remediation.

 


 

6. Vulnerability Handling Process & Timeline

Handling Process

Security Risk Report Receipt 

→ Acknowledgement 

→ Security Risk Vulnerability Verification & Risk Assessment 

→ Security Risk Remediation & Testing 

→ Security Update Release 

→ Public Disclosure

 

Response Timeline

 


 

7. Embargo Period and Disclosure Rules

7.1 Tiered Embargo Period

We set differentiated embargo periods based on Security Risk levels.

During the embargo period, we request that you refrain from publicly disclosing any information related to the Security Risk while we fully advance remediation work.

 

7.2 Emergency Early Disclosure Exemptions

We reserve the right to publicly disclose Security Risk information in advance if any of the following circumstances occur:

  • The Security Risk is being maliciously exploited, with evidence of large-scale ongoing attacks.
  • Security Risk information has been publicly disclosed by third parties.
  • The reporter breaches the embargo agreement and leaks Security Risk information in advance.

 


 

8. Safe Harbor Commitment

We solemnly commit that for security researchers who conduct good-faith, responsible Security Risk disclosure in compliance with this Policy:

  • We will not initiate any civil or criminal legal proceedings against you for submitting Security Risk reports.
  • We will not conduct network tracing or launch cyberattacks against you.
  • If you unintentionally violate relevant laws and regulations during Security Risk research, we will actively assist in resolving relevan
  • We will publicly acknowledge valuable Security Risk reports in official security advisories, subject to your written consent.

 


 

9. Security Advisories

All security advisories will be published on the Security Advisories section of our official website.

Each advisory will contain the following information:

  • Internal Security Risk ID and CVE ID, if applicable.
  • Affected product models and affected firmware version ranges.
  • Security Risk description, risk severity level, and impact scope.
  • Security update version number and download link.
  • User protection recommendations and temporary mitigation measures, where applicable.

 

For further information or to report a Security Risk, please use the official reporting channels provided above.

 


 

Back to Security Center >>