SMSEagle Coordinated Vulnerability Disclosure Policy

At Proximus Sp. z o.o. (owner of the SMSEagle brand) we treat the security of our products and systems as a priority. We apply a secure development lifecycle to build security into our products from design through development and release. Vulnerabilities still occur, and we want to learn about them as early as possible.

If you have found a security vulnerability in our products or systems, we would like to hear from you. This policy explains what we cover, how to report, and what you can expect from us.

Scope

This policy covers:

  • SMSEagle devices: software, firmware, system image, bootloader and hardware interfaces
  • SMSEagle API (v1 and v2) and integration plugins
  • smseagle.eu and its subdomains, including the online store
  • our support portal and knowledge base
  • IT infrastructure and services operated by Proximus Sp. z o.o.

Out of scope

The following are not accepted as vulnerabilities under this policy:

  • findings produced by automated scanners without a demonstrated, reproducible impact
  • missing security headers, cookie flags or TLS configuration preferences with no demonstrated attack path
  • absence of rate limiting or CAPTCHA, unless a concrete impact is shown
  • self-XSS, clickjacking on pages with no sensitive action, and issues requiring an already fully compromised device or account
  • social engineering, phishing, physical attacks and attacks on our staff, partners or suppliers
  • denial of service and resource exhaustion testing
  • software versions that have reached end of support, and configurations explicitly discouraged in our documentation
  • vulnerabilities in third party services that we do not operate
  • reports consisting solely of theoretical risk with no proof of concept

How to report

Send your report to security@smseagle.eu. Our PGP key is published at the end of this page.

Please include enough detail for us to reproduce the issue: the affected product and version or the affected URL, the configuration used, step by step reproduction instructions, and a proof of concept where applicable.

What we ask of you

  • Report as soon as you identify the issue.
  • Do not exploit the vulnerability beyond what is necessary to demonstrate it. Do not access, modify, delete or exfiltrate data that is not yours, and do not degrade the availability of our services.
  • Do not run automated scanning against our production systems. Testing against your own device or your own instance is welcome.
  • Do not attempt social engineering, phishing, or attacks on physical security.
  • Keep the details of the issue confidential until we have published a security advisory, or until the disclosure deadlines set out below have passed.
  • Comply with applicable law.

Legal position

Proximus Sp. z o.o. will not pursue legal action against researchers who report a vulnerability voluntarily, in good faith, and in accordance with this policy.

What you can expect from us

Stage

Our commitment

Acknowledgement of your report

within 3 business days, from a named person, not an autoresponder

Triage result (confirmed or not confirmed)

within 10 business days of your report

Severity assessment

CVSS 4.0, score and vector shared with you

Appeal, if we do not confirm the issue

you may submit additional evidence within 14 calendar days

Patch validation

we send you the fix before publication and ask for your feedback within 10 calendar days, or 5 business days for critical issues

Notification

we inform you when the fix is released and when the advisory is scheduled

Credit

we name you in the advisory if you wish, and only with your consent

Remediation timelines

Measured from the date we confirm the vulnerability.

Severity (CVSS 4.0)

Fix released within

Critical (9.0 to 10.0)

14 calendar days, out of cycle hotfix

High (7.0 to 8.9)

30 calendar days

Medium (4.0 to 6.9)

90 calendar days, or the next scheduled release

Low (0.1 to 3.9)

the next scheduled release, no later than 180 calendar days

Advisory publication

We publish a security advisory on smseagle.eu after the fix is released: within 14 calendar days for critical issues, 30 for high, 60 for medium and 90 for low.

Where a fix requires a firmware update on devices already deployed at customer sites, we may extend advisory publication by up to 90 additional calendar days, and in no case beyond 180 calendar days from the release of the fix. We will tell you if we apply this extension and why.

If a vulnerability is already public, described by a third party, or actively exploited, we publish the advisory immediately, alongside or ahead of the fix, together with any available workaround or mitigating measure.

 

Coordination and reporting to authorities

We may request a CVE identifier for a confirmed vulnerability and coordinate disclosure with a CSIRT or CNA. Where required by law, including Regulation (EU) 2024/2847, we report actively exploited vulnerabilities and severe incidents to ENISA and to the relevant CSIRT.

We handle your report confidentially. We do not share your personal data with third parties without your consent, except where disclosure is required by law. Reports to authorities do not include your personal data unless you have agreed to be named.

Rewards

We do not operate a bug bounty programme and we do not pay financial rewards for vulnerability reports, for any product, system or website in scope. We recognise contributions through public credit in our security advisories, with your consent. Please take this into account before deciding to report.

Our PGP Public Key

				
					-----BEGIN PGP PUBLIC KEY BLOCK-----mDMEZjiINhYJKwYBBAHaRw8BAQdAsgX2t/BsUvGJYe/6K3Dp1PvA/hr0kVkvutqFDHKUxcO0LVNNU0VhZ2xlIFNlY3VyaXR5IFRlYW0gPHNlY3VyaXR5QHNtc2VhZ2xlLmV1PoiZBBMWCgBBFiEElKVX0UISwmVJkQdNob6WMsGDtLYFAmY4iDYCGwMFCQWjvGoFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQob6WMsGDtLaY6AEAg7a9XuMid7KaB2gkCWDq5aqJe8pbK50w6qaRxx/JalwBANO2Pq/qv5UZ00thNw2+h62EIV6VfncNyn4p5Lmm5nwFuDgEZjiINhIKKwYBBAGXVQEFAQEHQJT0tWYA/jleMBd7L6eJ49O0r3DbGy/Zm6rEdPrntd90AwEIB4h+BBgWCgAmFiEElKVX0UISwmVJkQdNob6WMsGDtLYFAmY4iDYCGwwFCQWjvGoACgkQob6WMsGDtLZWlgD/Q8B7a3fX/0Ocxujv/rWdCR/8MfTPCz9FBoStDuaoxZYA/1gEdsLcoioCA5rEK+WVxwgIBzE4RL947Ym+Re2xmiAE=0UZs-----END PGP PUBLIC KEY BLOCK-----
				
			

Version 02, effective 2026-09-16. Previous version: 2025-09-15.