Vulnerability Disclosure Policy

The official external-facing PSIRT page of GoodWe (Product Security Incident Response Team) complies with the EU Cyber Resilience Act (CRA) and implements Coordinated Vulnerability Disclosure (CVD) in accordance with ISO/IEC 29147 and ISO/IEC 30111 standards.

Vulnerability Disclosure Policy

This page is the official public page of GoodWe Product Security Incident Response Team (PSIRT).

GoodWe’s Vulnerability Disclosure Policy is designed to meet the compliance requirements of the EU Cyber Resilience Act (CRA, EU 2024/2847). It serves as the official vulnerability response and disclosure mechanism, maintained and administered by the GoodWe Product Security Incident Response Team (PSIRT). This policy implements Coordinated Vulnerability Disclosure (CVD) in strict accordance with ISO/IEC 29147 and ISO/IEC 30111.

Vulnerability Handling

The vulnerability handling process covers vulnerability intake, assessment and validation, risk mitigation, patch development, security advisory publication, as well as supporting compliance activities such as product security‑support‑period disclosure.

Compliant Research

GoodWe respects and supports good‑faith, compliant cybersecurity research activities. We advocate responsible Coordinated Vulnerability Disclosure. Researchers are welcome to report cybersecurity vulnerabilities in GoodWe products to help secure end‑user devices and systems. To the extent permitted by applicable law, GoodWe will not pursue legal action against researchers who discover and report vulnerabilities in good faith and in full compliance with this disclosure policy.

Coordinated Vulnerability Disclosure Principles

Please submit vulnerability details to us privately in the first instance. Joint public disclosure of vulnerability information shall take place only after GoodWe has completed vulnerability validation, security patch development and notifications to affected users. This practice prevents malicious exploitation of vulnerabilities and protects end‑user safety.

Important Regulatory Notice: Where a vulnerability is confirmed to be actively exploited, GoodWe shall fulfil its statutory obligations under Article 14 of the Cyber Resilience Act (CRA), and submit vulnerability notifications to the EU CSIRT Network via the EU Single Reporting Platform within statutory deadlines. This is a mandatory legal obligation which shall be triggered in accordance with statutory timelines without waiting for patch development to be completed. A final report shall be submitted within 14 days after corrective or mitigating measures become available.

Scope of This Policy

This policy only covers cybersecurity vulnerabilities inherent to the product itself. Ordinary device malfunctions, after‑sales issues, and device configuration‑or‑usage‑related problems fall outside the scope of PSIRT handling. Please contact regular customer‑service channels for such matters.

Policy Update Date: 2026‑09‑10

Basic Principles of Vulnerability Management

GoodWe has established a standardized vulnerability‑handling system to define core criteria and control requirements for vulnerability management. The specific principles are set out below:

01

Standardized Handling and Responsibility Management

Define product vulnerability‑handling specifications, working criteria and respective responsibilities. Implement standardized control over the full lifecycle including vulnerability intake, analysis, remediation and disclosure to ensure compliant, orderly and traceable vulnerability handling.

02

Pre‑emptive Confidentiality Control for Vulnerability Information

A confidentiality mechanism for vulnerability information shall be enforced. Prior to the delivery of vulnerability fixes and resolution plans, non‑public vulnerability information shall be strictly controlled. Premature disclosure is prohibited to prevent the spread of security risks.

03

Dynamic, Risk-Based Management of Vulnerability Remediation Timelines

For general vulnerabilities, tailored remediation plans shall be formulated based on risk level, remediation complexity and supply‑chain coordination conditions. For high‑risk vulnerabilities confirmed to be actively exploited, GoodWe shall comply with CRA statutory time‑limits and implement remedial measures and regulatory reporting without undue delay.

04

Routine Testing and Process Iteration

Implement regular security testing and process review mechanisms. Continuously optimize vulnerability‑handling workflows and security strategies through lessons‑learned activities to progressively improve product vulnerability governance capabilities.

05

Multi‑dimensional Risk Governance and Multi‑party Collaboration

Fulfil primary product‑security accountability and establish a cross‑team collaborative handling mechanism.
The R&D department maintains product SBOMs, performs vulnerability remediation and delivers security updates; customer‑service channels conduct initial intake and forwarding of security‑related issues; the legal department provides compliance review and legal‑risk‑assessment support. All security‑vulnerability cases are centrally managed by the PSIRT.
Identify key stakeholders including internal departments, supply‑chain partners and open‑source‑component maintainers. Conduct synchronized outreach upon disclosure of major security vulnerabilities. Build closed‑loop full‑lifecycle governance capabilities covering pre‑emptive prevention, in‑process control and post‑event optimization, so that products maintain security‑compliance status throughout their support lifecycle.

06

Integrated Component Vulnerability Handling Mechanism

When a vulnerability is identified in a third-party or open-source component integrated into our products, we will notify the upstream component vendor or maintainer of the vulnerability. If we develop a remediation solution for the component vulnerability, we will share the corresponding remediation code or relevant documentation with the upstream maintainer.

07

User Notification Commitment for Security Incidents

If we confirm that a vulnerability in our products is being actively exploited in the wild, or that a serious cybersecurity incident as defined by the CRA has occurred, we will proactively notify affected users and provide information on mitigation measures and remediation solutions.

Vulnerability Reporting

We attach great importance to product security and end‑user interests. Security researchers are welcome and encouraged to report cybersecurity vulnerabilities found in our products.

Channel 1: Dedicated PSIRT security email

security@goodwe.com.cn

We recommend that you encrypt the email body and attachments using PGP (Pretty Good Privacy). You can click here to obtain GoodWe's PGP public key (UID: GoodWe Security Team: security@goodwe.com.cn; algorithm: RSA 4096; PGP fingerprint: CA81 9AA0 092B F89F 43BD 8AC1 9361 D996 CB45 0206).

Channel 2: Hotline:

+49 32 221092721

Service hours: 09:00‑17:00 on business days.

在线提交漏洞报告表单预留

下方为表单结构预留区,后端接入后可正常提交。当前仅作 UI 演示,请通过 PSIRT 邮箱或售后专线提交。

表单入口已保留 UI 位置,字段布局为:报告人信息 + 漏洞信息 + 附件 + 提交。后端接口待对接。
提交即表示您同意 协调披露约定。报告可匿名,可选是否在公告中署名致谢。

Recommended Report Content

  • Brief vulnerability description
  • Affected product series, specific models and firmware versions
  • Detailed vulnerability reproduction steps
  • Vulnerability proof materials (screenshots, POCs, etc. Do not disclose any unpublished 0-day vulnerabilities)
  • Reporter contact information (optional; anonymous submission is supported)
  • Authorization for public acknowledgement in security advisories (optional)
Notice: Do not disseminate any technical details of undisclosed vulnerabilities to prevent malicious exploitation and protect end-user security.

Vulnerability Response Statement

GoodWe will conduct response and handling activities for submitted vulnerability reports in accordance with the rules below.

Report Acknowledgement

Upon receipt of a vulnerability report, we will complete initial verification within 7 calendar days, send an acknowledgement to the reporter, and assign a unique vulnerability‑tracking ID for end‑to‑end progress communication.

Vulnerability Severity Classification

Vulnerability severity is determined based on CVSS 3.1 / 4.0 base scores, combined with practical exploitability and business‑context impact scope.

Handling Timeline Description

Timelines for vulnerability validation, risk assessment and security‑patch development are determined by comprehensive evaluation of vulnerability risk level, product‑architecture characteristics, and impact scope of third‑party components (SBOM).

Updates on Vulnerability Handling Progress

From the receipt and acceptance of a valid vulnerability report until the case is closed, we will provide the reporter with regular updates on the progress of our handling and remediation efforts. Under normal circumstances, the status will be updated at least once every 14 calendar days. For critical vulnerabilities, updates will be provided more frequently. If we anticipate that remediation cannot be completed within the target timeframe, we will proactively inform the reporter of the reason for the delay, the current progress, and the revised estimated remediation timeline.

Ongoing Communication and Embargo Mechanism

During coordinated vulnerability response, we maintain ongoing communication with the reporter to provide timely updates on vulnerability acknowledgment, analysis progress, remediation plan and estimated release timeline. An embargo period may be mutually agreed upon by both parties. Within the agreed embargo window, the reporter agrees not to publicly disclose vulnerability details. After the embargo expires, we will publish vulnerability advisory and security updates as scheduled. In circumstances posing risks to public safety, both parties may renegotiate and adjust the disclosure timeline.

Coordinated Disclosure Agreement

We ask reporters to follow the principles of Coordinated Vulnerability Disclosure (CVD). Before we officially release a security patch and accompanying security advisory, please refrain from publicly disclosing or disseminating any technical details related to the vulnerability. This helps prevent malicious attackers from exploiting the vulnerability and causing security risks to end users.

Thank you for your support and contributions to our product‑security efforts.

Vulnerability‑Handling Progress Inquiry

You may obtain updates on vulnerability‑handling progress via email or telephone.

Check processing progress

After submitting a vulnerability report, you will receive a unique vulnerability tracking number, which can be used to check the status of your report at any time through the following channels.

Security Advisories

2 Security Advisories
Advisory IDAdvisory TitleRelease DateAffected ProductsCVE IDSeverity LevelDetails
SEC‑2026‑0002 Deserialization of Untrusted Data Vulnerability in fastjson 2026-09-10 SEMS+ platform CVE‑2022‑25845 High More →
SEC‑2026‑0001 Open‑Redirect Vulnerability in react‑router‑dom Component 2026-09-10 SEMS+ platform CVE-2026-40181 Medium More →

Product Safety Support Lifecycle

The security support period refers to the period during which we continuously provide firmware security patches and vulnerability remediation for the corresponding product family.

In accordance with the requirements of the CRA, we provide security vulnerability patch support for all our products with digital elements for a minimum of five years from the date they are placed on the EU market.


Security updates are digitally signed, and the authenticity and integrity of the update package are automatically verified before installation on the device. Update packages are transmitted through an encrypted channel and support the automatic installation of security updates.


All security updates released during the product’s official support period will be provided to users free of charge. Once released, such security updates will remain available for at least 10 years. No patch fees or additional subscription fees are required to access these security updates.


End of Security Support

The end of security support does not affect routine warranty services provided during the hardware warranty period, nor does it mean that the product can no longer be used normally. It only means that security protections and support related to security vulnerabilities have ended.

Advance Notification Rules

We will release advance notices via official channels prior to the formal end of security support for products. We will endeavour to issue warning advisories no less than six months in advance to facilitate users’ planning for product upgrades and replacements.Notification channels include: official website security‑advisory column, targeted notification emails to customers. For products with human‑machine‑interaction interfaces, end‑of‑support reminders will be pushed where technically feasible.

Service Boundaries After End‑of‑Support

After the formal end‑of‑security‑support, the following services will be discontinued for the corresponding product family.

1. No new security firmware updates or vulnerability remediation patches will be released. 

2. No new vulnerability remediation services or security‑related technical consultations will be provided for this product. Vulnerability reports will still be accepted to fulfil statutory notification obligations for high‑risk vulnerabilities.

Risk Warning

Products that have reached the end of their security support period will no longer receive the latest vulnerability protections. Continued use while connected to the internet may therefore pose corresponding security risks.

We recommend migrating to a product version that is still within its security support period as soon as possible to help ensure the security of your device operation.

Security firmware updates released for a product during its security support period will remain publicly accessible after the end of the support period.

NEWSLETTER

Get industrial insights and GoodWe news here.

GoodWe Technologies Co., Ltd.

GoodWe Technologies Co., Ltd. Data Protection Declaration

GOODWE Solar Academy

GOODWE Solar Academy Data Protection Declaration

JOY TO INSTALL

Subscribe to the GoodWe Newsletter

Insert your details below to receive information

What type of Goodwe User are you?...

Retailer

Distributor

End User

Others

Enter Verification Code:*

By registering, you consent to receiving the newsletter via GetResponse and to interest analyses by evaluating individual opening and click rates. You can revoke your consent at any time with effect for the future and without giving reasons, e.g. by clicking on the unsubscribe link at the end of each newsletter. Further information on the processing of your data can be found in our Privacy Policy.