At Proximus Sp. z o.o. (owner of the SMSEagle brand) we treat the security of our products and systems as a priority. We apply a secure development lifecycle to build security into our products from design through development and release. Vulnerabilities still occur, and we want to learn about them as early as possible.
If you have found a security vulnerability in our products or systems, we would like to hear from you. This policy explains what we cover, how to report, and what you can expect from us.
This policy covers:
The following are not accepted as vulnerabilities under this policy:
Send your report to security@smseagle.eu. Our PGP key is published at the end of this page.
Please include enough detail for us to reproduce the issue: the affected product and version or the affected URL, the configuration used, step by step reproduction instructions, and a proof of concept where applicable.
Proximus Sp. z o.o. will not pursue legal action against researchers who report a vulnerability voluntarily, in good faith, and in accordance with this policy.
Stage | Our commitment |
Acknowledgement of your report | within 3 business days, from a named person, not an autoresponder |
Triage result (confirmed or not confirmed) | within 10 business days of your report |
Severity assessment | CVSS 4.0, score and vector shared with you |
Appeal, if we do not confirm the issue | you may submit additional evidence within 14 calendar days |
Patch validation | we send you the fix before publication and ask for your feedback within 10 calendar days, or 5 business days for critical issues |
Notification | we inform you when the fix is released and when the advisory is scheduled |
Credit | we name you in the advisory if you wish, and only with your consent |
Measured from the date we confirm the vulnerability.
Severity (CVSS 4.0) | Fix released within |
Critical (9.0 to 10.0) | 14 calendar days, out of cycle hotfix |
High (7.0 to 8.9) | 30 calendar days |
Medium (4.0 to 6.9) | 90 calendar days, or the next scheduled release |
Low (0.1 to 3.9) | the next scheduled release, no later than 180 calendar days |
We publish a security advisory on smseagle.eu after the fix is released: within 14 calendar days for critical issues, 30 for high, 60 for medium and 90 for low.
Where a fix requires a firmware update on devices already deployed at customer sites, we may extend advisory publication by up to 90 additional calendar days, and in no case beyond 180 calendar days from the release of the fix. We will tell you if we apply this extension and why.
If a vulnerability is already public, described by a third party, or actively exploited, we publish the advisory immediately, alongside or ahead of the fix, together with any available workaround or mitigating measure.
We may request a CVE identifier for a confirmed vulnerability and coordinate disclosure with a CSIRT or CNA. Where required by law, including Regulation (EU) 2024/2847, we report actively exploited vulnerabilities and severe incidents to ENISA and to the relevant CSIRT.
We handle your report confidentially. We do not share your personal data with third parties without your consent, except where disclosure is required by law. Reports to authorities do not include your personal data unless you have agreed to be named.
We do not operate a bug bounty programme and we do not pay financial rewards for vulnerability reports, for any product, system or website in scope. We recognise contributions through public credit in our security advisories, with your consent. Please take this into account before deciding to report.
-----BEGIN PGP PUBLIC KEY BLOCK-----mDMEZjiINhYJKwYBBAHaRw8BAQdAsgX2t/BsUvGJYe/6K3Dp1PvA/hr0kVkvutqFDHKUxcO0LVNNU0VhZ2xlIFNlY3VyaXR5IFRlYW0gPHNlY3VyaXR5QHNtc2VhZ2xlLmV1PoiZBBMWCgBBFiEElKVX0UISwmVJkQdNob6WMsGDtLYFAmY4iDYCGwMFCQWjvGoFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQob6WMsGDtLaY6AEAg7a9XuMid7KaB2gkCWDq5aqJe8pbK50w6qaRxx/JalwBANO2Pq/qv5UZ00thNw2+h62EIV6VfncNyn4p5Lmm5nwFuDgEZjiINhIKKwYBBAGXVQEFAQEHQJT0tWYA/jleMBd7L6eJ49O0r3DbGy/Zm6rEdPrntd90AwEIB4h+BBgWCgAmFiEElKVX0UISwmVJkQdNob6WMsGDtLYFAmY4iDYCGwwFCQWjvGoACgkQob6WMsGDtLZWlgD/Q8B7a3fX/0Ocxujv/rWdCR/8MfTPCz9FBoStDuaoxZYA/1gEdsLcoioCA5rEK+WVxwgIBzE4RL947Ym+Re2xmiAE=0UZs-----END PGP PUBLIC KEY BLOCK-----
Version 02, effective 2026-09-16. Previous version: 2025-09-15.