Comba Security Advisories provide information about identified security vulnerabilities affecting Comba products, including vulnerability details, affected products, security updates, and recommended mitigation measures.
We continuously monitor, investigate, and address security issues to help customers maintain secure and reliable product deployments.
(Currently no published security advisories.)
No security advisories have been published at this time. Please check this page regularly for future updates.
Email: Email住址會使用灌水程式保護機制。你需要啟動Javascript才能觀看它
Comba welcomes security researchers, customers, and partners to responsibly report potential security vulnerabilities identified in our products.
To help us investigate and resolve reported issues efficiently, please provide the information requested in the Vulnerability Report Template.

Download the TEMPLATE and submit your completed report to:
Email: Email住址會使用灌水程式保護機制。你需要啟動Javascript才能觀看它
Comba attaches high importance to product cybersecurity. We welcome and thank global security researchers for responsibly disclosing security risks and product vulnerabilities to us.
We commit to:
This Policy applies to external security researchers, partners, and users who report security risks affecting Comba products available on the EU market, including hardware, firmware, and remote network management systems.
Exclusions
This Policy does not apply to:
As defined in Article 14(5) of the EU Cyber Resilience Act (CRA), a severe incident having impact on the security of a product (“Severe Security Incident”) can be based on either of the following:
The complete list of all third-party software components adopted by our products is available in the official released SBOM file in SPDX 2.3 format corresponding to each product version.
For native vulnerabilities of third-party components:
Comba provides the following official Security Risk reporting channels.
Encrypted Email
Email: Email住址會使用灌水程式保護機制。你需要啟動Javascript才能觀看它
These channels can be used for all vulnerability reports and are the preferred channels for reporting sensitive vulnerabilities.
Dedicated Hotline
Phone: +34 910 618 108
Availability: Monday to Friday, 9:00-18:00 (Madrid time)
The hotline is intended for immediate reporting of critical high-risk vulnerabilities and vulnerabilities under active exploitation.
Hardcopy Mail
Address: Calle Diego de León 69, esc. 1, 2A, 28006 Madrid
Purpose: Submission of formal written vulnerability reports and paper supporting materials.
To support efficient Security Risk verification and remediation, please include as much of the following information as possible in your submission:
For reports containing highly sensitive information, such as confidential Security Risk exploit codes and user data leakage, we strongly recommend communication via email.
Anonymous Security Risk reports are accepted.
If you choose to remain anonymous, we will not trace your identity. However, we may be unable to provide you with progress updates regarding Security Risk remediation.
Handling Process
Security Risk Report Receipt
→ Acknowledgement
→ Security Risk Vulnerability Verification & Risk Assessment
→ Security Risk Remediation & Testing
→ Security Update Release
→ Public Disclosure
Response Timeline

We set differentiated embargo periods based on Security Risk levels.
During the embargo period, we request that you refrain from publicly disclosing any information related to the Security Risk while we fully advance remediation work.

We reserve the right to publicly disclose Security Risk information in advance if any of the following circumstances occur:
We solemnly commit that for security researchers who conduct good-faith, responsible Security Risk disclosure in compliance with this Policy:
All security advisories will be published on the Security Advisories section of our official website.
Each advisory will contain the following information:
For further information or to report a Security Risk, please use the official reporting channels provided above.