Version: 1.2
Effective Date: September 11, 2026
Last Updated: September 11, 2026
Reporting Contact: [email protected]
1. Introduction
Chatsworth Products, Inc. (CPI) is committed to protecting the security and privacy of our customers and users. We value feedback from independent security researchers, clients, and partners, to whom we collectively refer to as “researchers”, to help us protect our hardware, firmware, and user ecosystems.
This Vulnerability Disclosure Policy (VDP) outlines our procedures for the following:
- Receiving vulnerability reports from researchers
- Responding to and addressing reported vulnerabilities
- Coordinating disclosure to protect our customers
- Ensuring compliance with Article 14 of the CRA
2. Scope
2.1 Covered Products
This policy applies to vulnerabilities in the following products:
- All CPI branded hardware products sold within the European Union that allow for remote access via various network accessible interfaces.
- All CPI manufactured peripherals connected to the covered hardware solutions and the associated run-time firmware on these peripherals.
- Firmware which communicates with third-party manufactured peripherals directly connected to the covered hardware products.
- If a reported vulnerability resides strictly within the third-party hardware, firmware, or software of the peripheral itself, CPI will act as a coordinating entity. We will securely triage the report, apply mitigations to our interface if possible, and forward the findings to the respective third-party vendor for remediation.
- Software utilities developed by CPI.
2.2 Out of Scope
The following are NOT covered under this policy:
- Third-party components not directly connected to CPI Products with digital elements.
- Vulnerabilities in products that are not sold by CPI in the European Economic Area and therefore not under the jurisdiction of the CRA.
- Physical security issues requiring physical access.
- Social engineering attacks, which include but are not limited to activities commonly referred to as phishing, voice phishing, spear fishing, whaling, impersonating executive or officers of a target entity, pretexting, baiting and business email compromise.
- Any Denial-of-Service testing, resource exhaustion attacks, or high-volume flooding directed against production systems, corporate infrastructure, or live customer deployments.
- All testing must be confined to isolated, non-production test benches or dedicated lab hardware.
- Issues in deprecated or end-of-life products.
3. Researcher Guidelines and Safe Harbor
3.1 Legal Protection
To encourage responsible security research, CPI pledges not to initiate legal action against researchers, provided they strictly adhere to the following operational boundaries:
- Strict lab isolation
- No production network intrusion
- Reverse engineering for vulnerability research
- No permanent disruption
- Coordinated disclosure
3.2 Strict Lab Isolation
Testing must be conducted exclusively on non-production PDU hardware owned or legitimately acquired by the researcher at the researcher’s facilities. The testing environment is expected to be physically or logically air-gapped from production business networks and utilize dedicated, controlled electrical inputs. Any testing that targets live utility feeds or attempts to propagate faults upstream or downstream of the isolated test bench is outside the scope of safe harbor.
3.3 Production Network Intrusion
Researchers must never attempt to access, scan, or exploit any CPI Product deployed within operational customer environments, private networks, or data center infrastructures. Researchers are strictly prohibited from targeting, scanning, or interacting with any CPI Product that is deployed in an active production environment, enterprise datacenter, customer cabinet, or live server infrastructure.
3.4 Reverse Engineering for Vulnerability Research
CPI permits the disassembly, decompilation, and reverse engineering of our product firmware, binaries, and communication protocols solely for the purpose of identifying, analyzing, and reporting security vulnerabilities. Reverse engineering for any other purpose, including but not limited to cloning product features, extracting proprietary power management algorithms, developing competing products, or intellectual property theft is strictly prohibited and invalidates all protections under this VDP. Any tools or findings generated during reverse engineering, whether covered by this VDP, must remain strictly confidential under this VDP.
3.5 No Permanent Disruption
Performing any physical damage testing, high-voltage manipulation outside technical specifications, or destructive firmware modification is prohibited. This includes, but is not limited to, modifications that result in the permanent physical destruction of the PDU (such as disabling electrical safety overrides or bricking flash memory chips beyond factory recovery). If a test risks rendering a device permanently inoperable, researchers must halt all testing and consult with CPI engineering.
3.6 Coordinated Disclosure
All discovered vulnerability details must be kept strictly confidential and should be promptly reported to CPI only. The researcher shall not disclose the discovered vulnerability to any other entity, even after an official mitigation or patch has been released by CPI. The disclosure of the vulnerability shall only be reported by CPI.
4. How to Report a Vulnerability
4.1 Critical Accountability Disclaimer
CRITICAL COMPLIANCE NOTICE FOR REPORTERS: CPI utilizes automated routing utilities to monitor our security inbox and instantly alert our emergency incident response team. If a reporter fails to adhere to the explicit reporting guidelines detailed below—specifically the mandatory subject line prefixes—our automated systems will be unable to identify, categorize, and escalate an active exploit. CPI cannot guarantee, and shall not be liable for, meeting the expedited timelines defined in our response protocols if the submission does not follow the following reporting requirements. Among other things, CPI will verify each reporting researcher; accordingly, anonymous reports cannot be accepted or acted upon by us.
4.2 Email Submission Instructions
If you discover a potential or actively exploited security flaw in a CPI Product, please submit your findings immediately in a vulnerability report to our dedicated security team via email.
Reporting Email: [email protected]
The email subject line must follow one of the following formats, based on vulnerability type:
- “CRITICAL: ACTIVELY EXPLOITED VULNERABILITY – [Model Series] -Firmware Version [X.XX.XXXX]”
- This is to be used for reporting an actively exploited vulnerability.
- “Vulnerability Report – [Model Series] – Firmware Version [X.XX.XXXX]”
- This is to be used for reporting a general finding of a vulnerability that has no evidence of being actively exploited.
In both cases, please replace the [Model Series] with the respective model series of the product (such as Monitored, Switched Pro, etc.) and the [X.XX.XXXX] with the firmware version of the product.
4.3 Actively Exploited Vulnerability Report Information
A report of this type should only be submitted if you have evidence that a vulnerability is currently being actively exploited in a production environment. If that is the case, please provide the following information to help us understand and reproduce the vulnerability:
- Your contact information (name, email, organization if applicable)
- Product details including model series, configuration ID, part number, and currently running firmware version
- Vulnerability type (e.g., buffer overflow, injection, authentication bypass)
- Brief description of the vulnerability
- Observed indicators of compromise including but not limited to packet captures or logs showing the exploit in action (e.g.: system reboots, unauthorized control and configuration, etc.)
- Assessment of the operational impact
- Currently identified mitigations or workarounds
- Any information related to reproducing the actively exploited vulnerability that can be provided
4.4 General Vulnerability Report Information
A report of this type should be submitted for general finding of a vulnerability discovered during controlled laboratory testing, permitted reverse engineering, or source code analysis with zero evidence of active real-world abuse. If that is the case, please provide the following information to help us understand and reproduce the vulnerability:
- Your contact information (name, email, organization if applicable)
- Product details including: model series, configuration ID, part number, and current firmware version
- Vulnerability type (e.g., buffer overflow, injection, authentication bypass)
- Brief description of the vulnerability
- Initial severity assessment with CVSS metric if available
- Any relevant CVE and CWE numbers related to the vulnerability
- Step-by-step instructions and/or any scripts that can be run to reproduce the issue
- Any logs or packet captures demonstrating the vulnerability
5. Our Commitment to You
5.1 Availability
The CPI Product Security Team operates during standard business hours: Monday through Friday, 9:00 AM to 5:00 PM [CST/CDT], excluding public holidays.
5.2 General Vulnerability Report Response
Once we receive a general vulnerability report from a researcher, we will endeavor to adhere to the following timeline:
- Initial Acknowledgment: Within 24 hours of receiving your report an automated confirmation receipt will be generated to track your submission. Human engineering review begins on the next business day.
- Reproduction Confirmation: Within 7 business days after acknowledgement if our engineering team cannot reproduce a reported vulnerability using our standard lab environments, we will request additional technical details (such as packet captures, configuration files, or environmental parameters) from the reporter. The timeline for both confirmation and remediation will be paused until the necessary data is provided. Submissions lacking sufficient technical evidence to reproduce the flaw will be closed after 14 business days of inactivity.
- Severity Assessment: Within 1 business day after reproduction confirmation an assessment will be conducted using the most recently published version of the Common Vulnerability Scoring System (currently, CVSS v4.0). If the flaw represents a unique vulnerability in our proprietary software, CPI will reserve a unique CVE tracking identifier at this stage.
- Remediation Development: Within 40 business days after severity assessment is complete CPI engineering will develop a code fix and conduct comprehensive regression testing. Because our products regulate critical data center physical infrastructure, testing cannot be accelerated at the expense of electrical, thermal, or mechanical safety.
- Disclosure Coordination: Between 7 to 14 business days before our planned patch release CPI will draft the public security advisory and share it with the reporting researcher to align on technical content and coordination credits.
- Patch Release and Advisory Publish: Within 10 business days after completion of the remediation phase. CPI will upload the authenticated firmware patch to our secure customer download portal along with release notes documenting the unique CVE identifier, if there is one. Simultaneously, the final security advisory will be published to our publicly accessible website.
CPI believes in transparent, structured communication throughout the remediation process. To ensure reporting researchers are kept informed while protecting our engineering pipeline, we endeavor to adhere to the following communication standards:
- Periodic Progress Reports: During the remediation development phase (Step 4), CPI will proactively provide the reporting researcher with a status update every 15 business days or promptly upon reaching major milestones such as a successful patch validation.
- Ad-Hoc Inquiries: Reporting researchers are welcome to request a status check if a milestone interval passes without communication. To preserve engineering resources, we ask that automated, high-frequency status pings be avoided as this can also slow down response time.
- Mutual Confidentiality: CPI will maintain open dialogue regarding our technical progress, and we require that the reporting researcher maintains strict confidentiality regarding all shared telemetry, draft advisories, and patch timelines.
Additionally, in the event of a general vulnerability report, with your permission, CPI will publicly credit your contribution in our official security advisory upon successful deployment of the firmware patch.
5.3 Actively Exploited Vulnerability Report Response
If CPI receives a report that confirms a CPI product vulnerability is being actively exploited in a production environment, we will promptly elevate the matter to our emergency response protocol. CPI is committed to protecting customer infrastructure and will endeavor to adhere to the following timeline:
- Acknowledgment of Report: Within 24 hours of receiving your report, an automated confirmation receipt will be generated to verify your submission has entered our tracking system and is flagged as a critical active exploit. Human technical engineering review and active verification will begin on the next business day.
- Mandatory European Authority Notification: Within 24 hours of receiving your report, in accordance with Article 14 of the CRA, CPI shall formally report the vulnerability and active exploit via the ENISA reporting platform and the relevant national cyber security authorities.
- Emergency Customer Advisories (Workarounds): Within 72 hours of receiving your report, in accordance with Article 14 of the CRA, CPI will issue an urgent security advisory directly to affected users and data center clients without undue delay. This public notification will provide clear technical details regarding the threat alongside immediate, actionable workarounds—such as the general nature of the vulnerability and active exploit, an initial assessment, and corrective mitigating measures taken by us and to be taken by users, including any specific network isolation rules, firewall parameters, or port configuration changes, to allow operators to protect their live production systems while a permanent code fix, to the extent that may be required, is engineered.
- Expedited Hotfix Development: Target within 10 business days after sending an emergency customer advisory, CPI engineering will operate on an emergency remediation cycle to patch the source code. Because our products regulate critical physical infrastructure, emergency firmware will undergo rigorous regression testing to guarantee that power, thermal, and mechanical safety parameters remain stable under load.
- Emergency Patch Deployment: Within 14 calendar days after a corrective or mitigating measure becomes available (and not later than one month following of the 72-hour notice filed under CRA in the event of a “severe incident”), CPI will publish a final report in accordance with the CRA.
- Within 10 business days after completing the hotfix, CPI will publish an authenticated, signed firmware update on our secure customer download portal along with detailed release notes containing the unique tracking CVE identifier.
Due to the high-stakes nature of an active real-world threat, CPI endeavors to adjust its standard communication cadence to match the severity of the incident:
- Daily Crisis Updates: During an active exploit investigation, CPI will maintain daily direct communication with the reporting researcher or affected core enterprise stakeholders until mitigation options (Step 3) are published.
- Development Phase Updates: Once customer workarounds are published and the incident enters the Expedited Hotfix Development phase (Step 4), CPI will transition to a milestone-based update cadence. We will directly notify the reporting researcher and core enterprise stakeholders as frequently as every 48 to 72 hours with progress updates, and promptly upon successful completion of firmware safety and regression testing.
- Confidentiality: CPI requires that all specific exploit strings, proof-of-concept payloads, and operational vulnerabilities remain strictly confidential.
6. Policy Administration and Lifecycle
CPI reserves the right, in its sole and absolute discretion, to amend, modify or update this VDP at any time and from time to time as may be required by the CRA or other applicable laws, rules and regulations; to maintain alignment with evolving operational requirements and/or technical product lines; and for other business reasons and market conditions. Any such amendment, modification or update will become effective immediately upon the posting of the revised policy text on CPI’s website.
7. Questions and Legal Inquiries
For administrative questions, corporate compliance audits, or inquiries regarding the legal scope of this policy, or any security related questions unrelated to vulnerabilities, please contact CPI customer support at [email protected]. Do not submit technical product vulnerability data to this address; all technical disclosures must utilize the secure channel defined in Section 4 of this VDP.
8. Definitions
CPI Products: All products, both hardware and software, marketed and sold with CPI branding.
CRA: EU Cyber Resilience Act - regulation establishing cybersecurity requirements for products with digital elements.
CVSS: Common Vulnerability Scoring System - industry standard for assessing severity.
ENISA: European Union Agency for Cybersecurity.
© 2026 Chatsworth Products, Inc. All rights reserved.
Report a Security Vulnerability
Have you discovered a potential vulnerability in a CPI product or evidence that one is being actively exploited? Please report it promptly to our Product Security Team.
Before submitting your report, please review the reporting and encryption requirements outlined in this policy.