Ongoing Security Updates: We are committed to maintaining the security of all Grandstream products. Security updates will be provided for each product series as they become available, ensuring protection against emerging threats and vulnerabilities.
Scope of Support: Security updates apply to the full range of Grandstream products, offering consistent protection across our entire product offering.
How to Report a Security Vulnerability: If you've discovered a security vulnerability with a Grandstream product, software, or solution, you may submit this vulnerability here. Any submission will go to our Product Security Incident Response Team, and they will reach out with further questions if needed. Alternatively, click below to access our team's PGP Key for your submission and email our team here: psirt@grandstream.com
Please note that this form is not for technical support inquiries. For technical support, please contact our Help Desk support team here: https://helpdesk.grandstream.com/
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBGVWiCIBEADA4JuHIV38ITLEib
EzJyZVLar9aFfNp7B81yyiJx7T0J0M
a3Iz7bqJk+
CfBz2q6CAusvJwXl7PjWAjcv75noa2
1anaFsMOXn14ibW3Io2wtuWM4mxf0T
BcH4TUno41U4PSYdYk0AKqguyxJynw
qgsAFOm364Yo++
A0bdheUXcHB3k+
JWytq9N9/
PmJSDrUp5IoxkOTYaBKEKxkmgZkPV1
eqH3TVkY4dGAgJZHAjmBLpiP40oCRe
tD9Qcm9kdWN0IFNlY3VyaXR5IEluY2
QGdyYW5kc3RyZWFtLmNvbT6JAk4EEw
9gUCZVaIIgIbAwULCQgHAgYVCgkICw
D/
OqsyRzyeSemeskHCzlOY2qVY1CRu6X
06zdO+
PsGFtekwqEEC2pR6Eo2xm54ex35vPK
GEmrutmIDNvrONHLpwxcmpxvP2ckuT
fGUhRbQFhITmD7GQi38J0HQtr/
qu/FPQ712Gls5igpSsM9xjf5+
2X/qvGfR+l9H/
ZalfJHTaoqqOipY6u88MiRBEwFL6w7
fwvyMjEGJSFd+
dABiakxsRy/
4krCfBGlR1K69wrpoYXEF9Ly1IFPcA
uVrbHVlwBT4ccYI4qKnAF6kLUrGuIo
mtK5c8+S/+
T/
inKlD5m0PXLqjBiDktxgpPfB1VGWFT
0I7hRZ6IX6y3apI5DDEy5q1ZczmJNB
0eOYHjwvA6HzVql2HHxJ5MmJTv0nDi
OvoKNVjHbQOxC1V6Eqrwvk7Qhwftla
a2gMnJDrXtjdjMvr8qg9h2DKHr/
pswquUXQfD/x4gUwwZrHEeXb5/
JYnCVCpQ4qzPkCUP8YydINZ+
Q8oN+
yU4vjeFHT4pFR1bW2nh1h/
05rpK1q3zwcUGJWgckw5vtoyCDu1dE
cuY9Zq2qa752O0Vk1Y2Fhzd5ZiuP5q
q7Bw7Pkv073436xc6CM8lDFbzZKgTk
LE4OvetkZVTuYhz6iOS+
FP0OfVHJVBnZihvtqBMXJMq/+
Vf9cb2zCyLgEd7jEwdIPcW21X5ro3r
DNnyn3dnzrYNP4D2X2z59aTVbwcwZQ
4fYcVUx4xySzzbkeYDGgw3PoGKXq2Y
45h0PpgWC1eP34ip30i0ySOhQGNMYc
AYN699ZVa4WV+uyJb6H6MVvf9xjg+
=YlHq
-----END PGP PUBLIC KEY BLOCK-----
How do we Handle Potential Vulnerabilities: After you submit a report using the form on this website, we will classify and verify the vulnerability. If the vulnerability exists, we will contact the relevant department to deal with it and will respond with the results within 15 business days. All confirmed security vulnerabilities will be fixed within 90 days via software updates. All product vulnerability information belongs to Grandstream, and the vulnerability discoverer and the insider shall not release any vulnerability information without authorization.
Please do not do the following:
- Break any applicable law or regulations
- Access unnecessary, excessive, or significant amounts of data
- Use high-intensity invasive or destructive scanning tools to find vulnerabilities
- Engage in social engineering
- Execute or attempt to execute “Denial of Service” or “Resource Exhaustion” attacks
- Delete, alter, share, retain, or destroy the Organization's services or systems