Reporting security vulnerabilities

Please report vulnerabilities in NODER products to . A report should include the product model, firmware version and the steps needed to reproduce the issue. We do not require you to identify yourself — reports may be anonymous.

We acknowledge receipt within 5 working days and provide an initial assessment within 15 working days. Fixes are released without undue delay.

We ask that you do not disclose details publicly until a fix has been released or 90 days have passed since the report, whichever comes first; that you do not test on our customers' production systems without their consent; and that you do not copy third-party data. We will not take legal action against researchers acting in line with these rules and — with their consent — we credit them in the advisory.

Security advisories

We publish information about fixed vulnerabilities here. No advisory has been published to date.

Support period

We provide security updates free of charge for 10 years after a model is discontinued.

This policy implements the requirements of Regulation (EU) 2024/2847 (Cyber Resilience Act).

Last updated: 8 October 2026.

Scroll to Top