Technical support

Vulnerability Disclosure Centre

Process for receiving, assessing and handling reports of security vulnerabilities in NST devices and software.

NST will acknowledge receipt of a security vulnerability report within 3 working days of receiving a valid report. NST will carry out a preliminary assessment, classify the level of impact and update the reporter on the handling status periodically or whenever there is a significant change, until the vulnerability has been resolved or appropriate mitigation measures are in place. The specific handling time depends on the severity, the scope of impact, reproducibility and the actual technical conditions.

Process for handling security vulnerability information

Stage Handling time
Acknowledgement of receipt of a valid report Within 3 working days
Preliminary assessment and classification of the level of impact Within 7 working days
Handling and remediation According to the severity, scope of impact and actual technical conditions
  • Patch release: The schedule for the software or firmware update that fixes the issue will be communicated to the reporter in detail and published. Device firmware update guide

Contact point for security reports: NST Information Security Department. Email: [email protected]

List of security vulnerabilities

As of …, NST has not recorded any security vulnerabilities that have been confirmed and publicly disclosed for the camera/device lines currently being distributed. When a vulnerability is confirmed, the information will be published in the table below, including the description, severity, affected versions, patch and update instructions.

Vulnerability disclosure table

ID Description Affected product/version Severity Handling status Patched version Update instructions

Severity classification

NST classifies the severity of vulnerabilities into the following levels: Critical, High, Medium, Low. The classification is based on the scope of impact, exploitability, the impact on the confidentiality, integrity and availability of the system, and the effect on devices, firmware, cloud services, APIs/SDKs or integrated AI algorithms.

Addendum: patch update process

Security patches are released through firmware/system software or the corresponding update package. Users/partners are advised to update to the latest version in accordance with the release documentation and the accompanying technical guidance in the NST Connect mobile app and on NST’s official website.