Skip to Content (Press Enter) Skip to Footer (Press Enter)
It seems you are in a different country. Would you like to update your country selection?

Child Safety Month: Exclusive CYBEX Club Offer on Cloud T.

Skip to main section (Press Enter)

Vulnerability Disclosure Policy

Brand Commitment

At Cybex GmbH, providing safe and secure products and services is a fundamental priority. We are committed to protecting our customers, partners, products, and digital services from cybersecurity risks and to building relationships based on trust and confidence.

Data privacy and digital product security are therefore of high importance to Cybex GmbH.

We encourage customers, partners, security researchers, and other members of the security community to report, in good faith, any potential cybersecurity vulnerabilities they identify in Cybex products, applications, services, or digital infrastructure.

Cybex GmbH values and appreciates responsible vulnerability reporting. Reports from the security community help us identify security weaknesses, protect our customers, improve the security and reliability of our products and services, and continuously improve our vulnerability management processes.

This Vulnerability Disclosure Policy describes:

  • the products, systems, and services covered by this policy;
  • how potential vulnerabilities should be reported;
  • the rules for conducting good-faith security research;
  • how Cybex handles vulnerability reports;
  • expected response timeframes; and
  • how vulnerability disclosure may be coordinated.

This policy is reviewed at least annually and may be updated where necessary to reflect changes to our products, services, security practices, or applicable legal and regulatory requirements.

Scope

This policy applies to cybersecurity vulnerabilities affecting Cybex products with digital elements and supporting digital services for which Cybex GmbH is responsible.

This includes, where applicable:

  • Cybex mobile applications;
  • connected Cybex products and associated digital functionality;
  • device software and firmware;
  • Bluetooth and other digital interfaces;
  • Cybex-operated APIs;
  • backend services and remote data processing supporting Cybex products;
  • authentication and account-management services supporting Cybex products;
  • cloud-hosted components operated on behalf of Cybex;
  • web applications and publicly accessible Cybex digital services; and
  • software components integrated into Cybex products where a vulnerability could affect the security of a Cybex product.

Publicly accessible Cybex domains currently include:

  • *.cybex-online.com
  • *.goodbabyprod.com
  • *.gb-online.com
  • *.columbustp.com
  • *.goodbaby.eu
  • *.rollplay.com
  • gbinternational.com.hk
  • mycbx.com
  • cybex.link
  • cybex-online.com

The above list is not intended to prevent the reporting of vulnerabilities affecting another Cybex product with digital elements. If you believe you have identified a vulnerability affecting a Cybex product or service that is not explicitly listed, you may still report it through the reporting channels described below.

If you are uncertain whether a product, application, service, or digital asset is within scope, please contact us before performing additional testing.

Third-Party Systems and Components

Cybex products and services may integrate or depend on services, software, libraries, cloud platforms, or other components provided by third parties.

This policy does not authorize security testing of infrastructure, applications, accounts, or systems operated by third parties without their permission.

However, vulnerabilities affecting a Cybex product that originate from, or involve, a third-party software component or dependency may still be reported to Cybex through this process.

Where appropriate, Cybex may coordinate remediation with the relevant supplier, service provider, open-source project, or other affected party.

Safe Harbor

Cybex GmbH supports good-faith security research conducted in accordance with this policy.

Cybex will not initiate or support legal action against a security researcher for security research conducted in good faith and in compliance with this policy.

This assurance applies where the researcher:

  • makes a reasonable effort to comply with this policy;
  • acts for the purpose of identifying and reporting a cybersecurity vulnerability;
  • avoids unnecessary harm to Cybex, its customers, employees, partners, and third parties;
  • does not intentionally access, retain, alter, destroy, or disclose data beyond what is reasonably necessary to demonstrate the vulnerability; and
  • reports the vulnerability to Cybex without undue delay.

This safe harbor does not apply where recognizable malicious, fraudulent, criminal, or intelligence-related intentions exist.

If a third party initiates legal action against a researcher who has acted in accordance with this policy, Cybex may, where appropriate and legally permissible, confirm that the researcher conducted their activities in accordance with this policy.

This policy does not provide authorization to violate applicable laws or regulations.

Researchers who are uncertain whether particular research activities are permitted are encouraged to contact Cybex before proceeding.

Security Research Guidelines

When conducting security research under this policy, researchers are expected to act responsibly and minimize any potential impact on Cybex, its customers, and third parties.

Researchers should:

  • limit research to products, systems, and services within the scope of this policy;
  • use accounts, devices, and data that they own or are specifically authorized to use wherever possible;
  • perform only the minimum testing necessary to verify and demonstrate a potential vulnerability;
  • stop testing if it could negatively affect the availability, safety, confidentiality, or integrity of a product, service, system, or customer data;
  • avoid intentionally accessing personal data belonging to other users;
  • immediately stop testing and notify Cybex if sensitive or personal information is unintentionally accessed;
  • avoid copying, downloading, retaining, or transmitting data beyond what is necessary to demonstrate the vulnerability;
  • not establish persistence or maintain unauthorized access;
  • not perform lateral movement into other systems;
  • not upload unauthorized code or malware;
  • not modify or delete customer, business, configuration, or production data;
  • not perform denial-of-service or distributed denial-of-service attacks;
  • not perform phishing, spam, social engineering, or physical security attacks;
  • not perform brute-force or password-spraying attacks that could affect user accounts or service availability;
  • not test systems operated by third parties unless separately authorized by the relevant third party;
  • report identified vulnerabilities promptly using the official Cybex reporting channels; and
  • cooperate with Cybex where additional information is reasonably required to validate or remediate the reported vulnerability.

Automated security scanning alone is generally not sufficient for a vulnerability report. Automated findings should be accompanied by sufficient evidence and technical context to allow Cybex to understand and reproduce the issue.

Coordinated Vulnerability Disclosure

Cybex supports Coordinated Vulnerability Disclosure (CVD).

We ask security researchers to give Cybex a reasonable opportunity to investigate, remediate, mitigate, and, where necessary, provide security updates to affected users before detailed vulnerability information is publicly disclosed.

Researchers should coordinate the timing and content of public disclosure with Cybex.

Cybex will not require researchers acting in accordance with this policy to enter into a non-disclosure agreement as a condition for reporting a vulnerability.

Cybex will work with the reporting party in good faith to determine an appropriate disclosure timeline, taking into consideration:

  • vulnerability severity;
  • exploitability;
  • evidence of exploitation;
  • potential safety implications;
  • affected products and product versions;
  • number of potentially affected users;
  • availability of mitigations;
  • availability and deployment of security updates; and
  • risks associated with publicly disclosing technical details.

Cybex may request that publication of vulnerability details be temporarily delayed where immediate disclosure could significantly increase the cybersecurity risk to customers or affected products before reasonable mitigation is available.

This does not provide Cybex with an indefinite right to prevent disclosure. The objective is to coordinate disclosure so affected users can be reasonably protected.

Our Vulnerability Handling Process

Reported vulnerabilities are handled through the Cybex vulnerability management process.

Depending on the nature of the report, the process may include:

  1. Receipt
    The vulnerability report is registered and assigned for review.
     
  2. Initial Triage
    Cybex determines the affected product, application, service, component, or infrastructure and assigns the appropriate technical owner.
     
  3. Validation
    The technical team attempts to reproduce the reported vulnerability and determines whether the issue represents a valid security vulnerability.
     
  4. Security and Product Risk Assessment
    Cybex evaluates factors including:
    • severity;
    • exploitability;
    • potential impact;
    • affected versions;
    • customer impact;
    • data confidentiality, integrity, and availability;
    • possible product-safety implications;
    • evidence of active exploitation; and
    • whether a third-party component or dependency is involved.
       
  5. Remediation or Mitigation
    The responsible product or engineering team evaluates and implements an appropriate remediation, security update, configuration change, or mitigation.
     
  6. Verification
    Where appropriate, Cybex verifies that the remediation adequately addresses the identified vulnerability.
     
  7. Security Update and Customer Communication
    Where a security update or other customer action is necessary, Cybex will provide appropriate information to affected users.
     
  8. Coordinated Disclosure
    Where applicable, Cybex will coordinate disclosure with the reporting entity.
     
  9. Closure
    The vulnerability case is closed after the appropriate remediation, disclosure, communication, and documentation activities have been completed.

Response Timeframes

CYBEX aims to maintain clear and timely communication throughout the vulnerability-handling process.

Where the reporting entity has provided a valid contact method, CYBEX will use reasonable efforts to:

Activity Response Approach
Human acknowledgement of vulnerability report Acknowledge receipt as soon as reasonably practicable
Initial triage Perform an initial assessment based on the available information
Detailed feedback following initial analysis Provide further feedback once sufficient analysis has been completed
Validation status, where reasonably possible Communicate whether the vulnerability has been confirmed, where reasonably possible
Further status updates Provide updates as appropriate during investigation and remediation
Public disclosure Coordinate disclosure based on remediation progress, product risk, safety considerations, and other relevant factors

Response, investigation, and remediation timeframes may vary depending on the complexity and severity of the vulnerability, affected products, technical dependencies, safety implications, availability of mitigations, and involvement of third parties.

Vulnerabilities requiring significant product, software, firmware, or infrastructure changes may require additional investigation, testing, and remediation time.

CYBEX will aim to maintain reasonable communication with the reporting entity throughout the vulnerability-handling process.

Reporting a Vulnerability

Potential vulnerabilities should be reported to: it-security@cybex-online.com

Please use a clear subject line such as: Security Vulnerability Report – [Affected Product or Service]

Where possible, the report should contain:

  • affected product, application, service, domain, API, or component;
  • affected product or software version;
  • description of the vulnerability;
  • steps necessary to reproduce the issue;
  • proof of concept, where appropriate;
  • expected versus observed behavior;
  • timestamps relevant to the testing;
  • screenshots, logs, or other supporting evidence;
  • potential security impact;
  • possible customer or safety impact;
  • information regarding a potentially affected third-party dependency;
  • whether you are aware of exploitation occurring outside your own testing;
  • suggested remediation, if known; and
  • a contact method for follow-up questions.

Please do not send passwords, private cryptographic keys, authentication tokens, unnecessary personal data, or other sensitive information unless this information is essential to demonstrate the vulnerability.

Confidentiality and Personal Data

Cybex will treat vulnerability reports and information relating to unresolved vulnerabilities as confidential to the extent reasonably possible and permitted by law.

Personal information relating to a reporting entity will only be processed for legitimate purposes associated with receiving, investigating, remediating, and coordinating the reported vulnerability or where otherwise required by applicable law.

Cybex will seek to limit the sharing of the reporting entity's personal information to persons who reasonably require access to manage the vulnerability.

Where Cybex is legally required to provide vulnerability information to a competent cybersecurity authority, CSIRT, market-surveillance authority, ENISA, law-enforcement authority, or other competent authority, information will be provided in accordance with applicable legal obligations.

Regulatory Reporting

The vulnerability disclosure process is separate from Cybex's internal regulatory incident and vulnerability reporting obligations.

Vulnerabilities reported under this policy are assessed to determine whether additional notification or reporting obligations apply under relevant cybersecurity legislation, including the EU Cyber Resilience Act.

Where legally required, Cybex may notify the relevant competent authority, CSIRT, ENISA, or other authority.

The reporting entity is not responsible for determining whether a vulnerability meets Cybex's regulatory reporting obligations.

Third-Party Vulnerabilities

If a reported vulnerability originates from a third-party component that is incorporated into or used by a Cybex product, Cybex will assess the impact of that vulnerability on the Cybex product.

Where necessary, Cybex may coordinate with the supplier, software provider, open-source project, or other responsible party to facilitate remediation.

Researchers must not use this policy as authorization to test the third party's own infrastructure.

Researcher Recognition

Cybex appreciates responsible security research.

Where appropriate and with the explicit consent of the researcher, Cybex may publicly acknowledge researchers who responsibly report valid vulnerabilities.

Participation in this Vulnerability Disclosure Policy does not imply that Cybex operates a bug bounty or financial reward program unless explicitly stated otherwise.

Policy Review

This policy is owned by Cybex IT Security, with external commitments coordinated with Product Compliance.

The policy will be reviewed at least annually and whenever there are material changes to:

  • Cybex products or services;
  • vulnerability reporting channels;
  • vulnerability management processes;
  • applicable cybersecurity regulation; or
  • responsible organizational roles.

For questions regarding this policy or uncertainty concerning permitted security research, please contact: it-security@cybex-online.com