Global
Language
The official external-facing PSIRT page of GoodWe (Product Security Incident Response Team) complies with the EU Cyber Resilience Act (CRA) and implements Coordinated Vulnerability Disclosure (CVD) in accordance with ISO/IEC 29147 and ISO/IEC 30111 standards.
This page is the official public page of GoodWe Product Security Incident Response Team (PSIRT).
GoodWe’s Vulnerability Disclosure Policy is designed to meet the compliance requirements of the EU Cyber Resilience Act (CRA, EU 2024/2847). It serves as the official vulnerability response and disclosure mechanism, maintained and administered by the GoodWe Product Security Incident Response Team (PSIRT). This policy implements Coordinated Vulnerability Disclosure (CVD) in strict accordance with ISO/IEC 29147 and ISO/IEC 30111.
The vulnerability handling process covers vulnerability intake, assessment and validation, risk mitigation, patch development, security advisory publication, as well as supporting compliance activities such as product security‑support‑period disclosure.
GoodWe respects and supports good‑faith, compliant cybersecurity research activities. We advocate responsible Coordinated Vulnerability Disclosure. Researchers are welcome to report cybersecurity vulnerabilities in GoodWe products to help secure end‑user devices and systems. To the extent permitted by applicable law, GoodWe will not pursue legal action against researchers who discover and report vulnerabilities in good faith and in full compliance with this disclosure policy.
Please submit vulnerability details to us privately in the first instance. Joint public disclosure of vulnerability information shall take place only after GoodWe has completed vulnerability validation, security patch development and notifications to affected users. This practice prevents malicious exploitation of vulnerabilities and protects end‑user safety.
This policy only covers cybersecurity vulnerabilities inherent to the product itself. Ordinary device malfunctions, after‑sales issues, and device configuration‑or‑usage‑related problems fall outside the scope of PSIRT handling. Please contact regular customer‑service channels for such matters.
Policy Update Date: 2026‑09‑10
GoodWe has established a standardized vulnerability‑handling system to define core criteria and control requirements for vulnerability management. The specific principles are set out below:
Define product vulnerability‑handling specifications, working criteria and respective responsibilities. Implement standardized control over the full lifecycle including vulnerability intake, analysis, remediation and disclosure to ensure compliant, orderly and traceable vulnerability handling.
A confidentiality mechanism for vulnerability information shall be enforced. Prior to the delivery of vulnerability fixes and resolution plans, non‑public vulnerability information shall be strictly controlled. Premature disclosure is prohibited to prevent the spread of security risks.
For general vulnerabilities, tailored remediation plans shall be formulated based on risk level, remediation complexity and supply‑chain coordination conditions. For high‑risk vulnerabilities confirmed to be actively exploited, GoodWe shall comply with CRA statutory time‑limits and implement remedial measures and regulatory reporting without undue delay.
Implement regular security testing and process review mechanisms. Continuously optimize vulnerability‑handling workflows and security strategies through lessons‑learned activities to progressively improve product vulnerability governance capabilities.
Fulfil primary product‑security accountability and establish a cross‑team collaborative handling mechanism. The R&D department maintains product SBOMs, performs vulnerability remediation and delivers security updates; customer‑service channels conduct initial intake and forwarding of security‑related issues; the legal department provides compliance review and legal‑risk‑assessment support. All security‑vulnerability cases are centrally managed by the PSIRT.Identify key stakeholders including internal departments, supply‑chain partners and open‑source‑component maintainers. Conduct synchronized outreach upon disclosure of major security vulnerabilities. Build closed‑loop full‑lifecycle governance capabilities covering pre‑emptive prevention, in‑process control and post‑event optimization, so that products maintain security‑compliance status throughout their support lifecycle.
When a vulnerability is identified in a third-party or open-source component integrated into our products, we will notify the upstream component vendor or maintainer of the vulnerability. If we develop a remediation solution for the component vulnerability, we will share the corresponding remediation code or relevant documentation with the upstream maintainer.
If we confirm that a vulnerability in our products is being actively exploited in the wild, or that a serious cybersecurity incident as defined by the CRA has occurred, we will proactively notify affected users and provide information on mitigation measures and remediation solutions.
We attach great importance to product security and end‑user interests. Security researchers are welcome and encouraged to report cybersecurity vulnerabilities found in our products.
security@goodwe.com.cn
We recommend that you encrypt the email body and attachments using PGP (Pretty Good Privacy). You can click here to obtain GoodWe's PGP public key (UID: GoodWe Security Team: security@goodwe.com.cn; algorithm: RSA 4096; PGP fingerprint: CA81 9AA0 092B F89F 43BD 8AC1 9361 D996 CB45 0206).
+49 32 221092721
Service hours: 09:00‑17:00 on business days.
下方为表单结构预留区,后端接入后可正常提交。当前仅作 UI 演示,请通过 PSIRT 邮箱或售后专线提交。
GoodWe will conduct response and handling activities for submitted vulnerability reports in accordance with the rules below.
Upon receipt of a vulnerability report, we will complete initial verification within 7 calendar days, send an acknowledgement to the reporter, and assign a unique vulnerability‑tracking ID for end‑to‑end progress communication.
Vulnerability severity is determined based on CVSS 3.1 / 4.0 base scores, combined with practical exploitability and business‑context impact scope.
Timelines for vulnerability validation, risk assessment and security‑patch development are determined by comprehensive evaluation of vulnerability risk level, product‑architecture characteristics, and impact scope of third‑party components (SBOM).
From the receipt and acceptance of a valid vulnerability report until the case is closed, we will provide the reporter with regular updates on the progress of our handling and remediation efforts. Under normal circumstances, the status will be updated at least once every 14 calendar days. For critical vulnerabilities, updates will be provided more frequently. If we anticipate that remediation cannot be completed within the target timeframe, we will proactively inform the reporter of the reason for the delay, the current progress, and the revised estimated remediation timeline.
During coordinated vulnerability response, we maintain ongoing communication with the reporter to provide timely updates on vulnerability acknowledgment, analysis progress, remediation plan and estimated release timeline. An embargo period may be mutually agreed upon by both parties. Within the agreed embargo window, the reporter agrees not to publicly disclose vulnerability details. After the embargo expires, we will publish vulnerability advisory and security updates as scheduled. In circumstances posing risks to public safety, both parties may renegotiate and adjust the disclosure timeline.
We ask reporters to follow the principles of Coordinated Vulnerability Disclosure (CVD). Before we officially release a security patch and accompanying security advisory, please refrain from publicly disclosing or disseminating any technical details related to the vulnerability. This helps prevent malicious attackers from exploiting the vulnerability and causing security risks to end users.
Thank you for your support and contributions to our product‑security efforts.
You may obtain updates on vulnerability‑handling progress via email or telephone.
After submitting a vulnerability report, you will receive a unique vulnerability tracking number, which can be used to check the status of your report at any time through the following channels.
| Advisory ID | Advisory Title | Release Date | Affected Products | CVE ID | Severity Level | Details |
|---|---|---|---|---|---|---|
| SEC‑2026‑0002 | Deserialization of Untrusted Data Vulnerability in fastjson | 2026-09-10 | SEMS+ platform | CVE‑2022‑25845 | High | More → |
| SEC‑2026‑0001 | Open‑Redirect Vulnerability in react‑router‑dom Component | 2026-09-10 | SEMS+ platform | CVE-2026-40181 | Medium | More → |
The security support period refers to the period during which we continuously provide firmware security patches and vulnerability remediation for the corresponding product family.
In accordance with the requirements of the CRA, we provide security vulnerability patch support for all our products with digital elements for a minimum of five years from the date they are placed on the EU market.
Security updates are digitally signed, and the authenticity and integrity of the update package are automatically verified before installation on the device. Update packages are transmitted through an encrypted channel and support the automatic installation of security updates.
All security updates released during the product’s official support period will be provided to users free of charge. Once released, such security updates will remain available for at least 10 years. No patch fees or additional subscription fees are required to access these security updates.
The end of security support does not affect routine warranty services provided during the hardware warranty period, nor does it mean that the product can no longer be used normally. It only means that security protections and support related to security vulnerabilities have ended.
We will release advance notices via official channels prior to the formal end of security support for products. We will endeavour to issue warning advisories no less than six months in advance to facilitate users’ planning for product upgrades and replacements.Notification channels include: official website security‑advisory column, targeted notification emails to customers. For products with human‑machine‑interaction interfaces, end‑of‑support reminders will be pushed where technically feasible.
After the formal end‑of‑security‑support, the following services will be discontinued for the corresponding product family.
1. No new security firmware updates or vulnerability remediation patches will be released.
2. No new vulnerability remediation services or security‑related technical consultations will be provided for this product. Vulnerability reports will still be accepted to fulfil statutory notification obligations for high‑risk vulnerabilities.
Products that have reached the end of their security support period will no longer receive the latest vulnerability protections. Continued use while connected to the internet may therefore pose corresponding security risks.
We recommend migrating to a product version that is still within its security support period as soon as possible to help ensure the security of your device operation.
Security firmware updates released for a product during its security support period will remain publicly accessible after the end of the support period.
NEWSLETTER
Get industrial insights and GoodWe news here.
GoodWe Technologies Co., Ltd.
GoodWe Technologies Co., Ltd. Data Protection Declaration
JOY TO INSTALL