Report a Security Vulnerability

Thank you for helping us keep Unipi products and services secure.

Use this form to report security vulnerabilities in our websites and online infrastructure as well as in Unipi products. You may report anonymously — contact details are optional, but without them we cannot keep you informed about the resolution.

Before submitting, please read our Vulnerability Disclosure Policy.

Sensitive details can be submitted encrypted. If you prefer not to share technical details in plain text, encrypt your description with our PGP key stated in security.txt. Alternatively, submit a brief report without technical details and a way to reach you — we will get back to you and agree on a secure channel.

Web / Infrastructure

For vulnerabilities in our websites, e-shop or online infrastructure, please include:

  • the website, IP address or page where the vulnerability can be observed;
  • a brief description of the type of vulnerability, for example "XSS vulnerability";
  • steps to reproduce as a benign, non-destructive proof of concept. This helps us triage the report quickly and accurately and reduces the risk of duplicate reports or malicious exploitation.

Unipi products

For vulnerabilities in a Unipi product, please include:

  • product name and firmware/OS/software version;
  • description of the vulnerability and its impact;
  • prerequisites (configuration, wiring, network scenario, ...) required to reproduce the issue;
  • detailed step-by-step instructions to reproduce the issue;
  • proof-of-concept code, if available.

Report form

Describe the vulnerability, steps to reproduce and the impact. You can paste a PGP encrypted block here.