NST will acknowledge receipt of a security vulnerability report within 3 working days of receiving a valid report. NST will carry out a preliminary assessment, classify the level of impact and update the reporter on the handling status periodically or whenever there is a significant change, until the vulnerability has been resolved or appropriate mitigation measures are in place. The specific handling time depends on the severity, the scope of impact, reproducibility and the actual technical conditions.
Process for handling security vulnerability information
| Stage | Handling time |
|---|---|
| Acknowledgement of receipt of a valid report | Within 3 working days |
| Preliminary assessment and classification of the level of impact | Within 7 working days |
| Handling and remediation | According to the severity, scope of impact and actual technical conditions |
- Patch release: The schedule for the software or firmware update that fixes the issue will be communicated to the reporter in detail and published. Device firmware update guide
Contact point for security reports: NST Information Security Department. Email: [email protected]
List of security vulnerabilities
As of …, NST has not recorded any security vulnerabilities that have been confirmed and publicly disclosed for the camera/device lines currently being distributed. When a vulnerability is confirmed, the information will be published in the table below, including the description, severity, affected versions, patch and update instructions.
Vulnerability disclosure table
| ID | Description | Affected product/version | Severity | Handling status | Patched version | Update instructions |
|---|
Severity classification
NST classifies the severity of vulnerabilities into the following levels: Critical, High, Medium, Low. The classification is based on the scope of impact, exploitability, the impact on the confidentiality, integrity and availability of the system, and the effect on devices, firmware, cloud services, APIs/SDKs or integrated AI algorithms.
Addendum: patch update process
Security patches are released through firmware/system software or the corresponding update package. Users/partners are advised to update to the latest version in accordance with the release documentation and the accompanying technical guidance in the NST Connect mobile app and on NST’s official website.