1. Our Commitment
Comba attaches high importance to product cybersecurity. We welcome and thank global security researchers for responsibly disclosing security risks and product vulnerabilities to us.
We commit to:
- Provide safe harbor protection for security researchers who conduct good-faith and responsible vulnerability disclosure.
- Respond to vulnerability reports in a timely manner and maintain transparent communication.
- Verify and remediate security risks and release security updates where necessary.
- Publicly acknowledge contributors in official security advisories upon the reporter’s consent.
2. Scope of Application
This Policy applies to external security researchers, partners, and users who report security risks affecting Comba products available on the EU market, including hardware, firmware, and remote network management systems.
3. Safe Harbor Statement
Safe Harbor
Comba will not initiate civil or criminal legal proceedings against security researchers who submit vulnerability reports in good faith, follow this Policy, avoid malicious exploitation, and do not publicly disclose vulnerabilities before remediation.
This protection does not apply to activities including blackmail, malicious intrusion, data theft, public disclosure before remediation, or other malicious actions.
4. Vulnerability Reporting Channels
Official Vulnerability Reporting Channels
Comba provides the following official security risk reporting channels, available 24 hours a day, 7 days a week.
Encrypted Email
Email: Email住址會使用灌水程式保護機制。你需要啟動Javascript才能觀看它
Purpose: For all vulnerability reports. This is the preferred channel for reporting sensitive vulnerabilities.
Dedicated Hotline
Phone: +34 910 618 108
Purpose: For reporting critical high-risk vulnerabilities and vulnerabilities under active exploitation.
Hardcopy Mail
Address: Calle Diego de León nº69, Escalera 1, 2A, 28006 Madrid – Spain
Purpose: Submission of formal written vulnerability reports and supporting materials.
5. Vulnerability Report Requirements
To help us verify and remediate vulnerabilities efficiently, please provide the following information whenever possible:
- Vulnerability name, CWE ID (if available), and CVE ID (if available)
- Affected product model numbers and firmware versions
- Detailed and reproducible vulnerability exploitation steps
- Proof of Concept (POC) code or demonstration video (if available)
- Vulnerability impact scope and risk assessment
- Contact information for follow-up communication (optional)
6. Vulnerability Handling Process & Timeline
Handling Process
Security Risk Report Receipt
→ Acknowledgement
→ Vulnerability Verification
→ Risk Assessment
→ Remediation & Testing
→ Security Update Release
→ Public Disclosure
Response Timeline

7. Security Advisories
Comba publishes security advisories to provide information about identified vulnerabilities and available security updates.
Each advisory includes:
- Internal vulnerability ID and CVE ID (if applicable)
- Affected product models and firmware versions
- Vulnerability description, severity level, and impact scope
- Security update version and download link
- Recommended protection measures and temporary mitigation solutions