1. Purpose and Commitment
Promise
TiMOTION is a leading manufacturer of electric linear actuator systems. We are committed to the security and resilience of our products and to continuously improve our approach to identifying, assessing, and addressing potential security vulnerabilities.
This Vulnerability Disclosure Policy (VDP) explains how security researchers, customers, and business partners can report security vulnerabilities to TiMOTION, and how we assess, address, and communicate reported vulnerabilities.
This policy applies to TiMOTION products with digital elements placed on the European Union market within the scope of Regulation (EU) 2024/2847 (Cyber Resilience Act, or “CRA”), including smart linear actuators such as the T-Smart series, electric lifting columns, control boxes, related accessories, and associated mobile applications.
Our Commitment
Product security is a shared responsibility. We welcome vulnerability reports submitted in good faith and are committed to handling them responsibly, transparently, and collaboratively. These reports help us strengthen the security and resilience of our products and better protect our customers and partners.
2. Scope
In Scope:
We welcome reports of security vulnerabilities affecting TiMOTION hardware products, firmware, and mobile applications while they are within their support period (see Section 11. Support Period). Reports concerning any firmware or software version released during the support period may be submitted. While testing against the latest available version is encouraged, it is not required.
Out of Scope:
The following activities and issues are outside the scope of this vulnerability reporting process:
- Social engineering targeting TiMOTION employees or dealers
- Physical attacks against TiMOTION products or related services
- Denial-of-service (DoS) or resource-exhaustion testing
- Spam or mass credential attacks
- Vulnerabilities in third-party applications or services not maintained by TiMOTION (please report these directly to the relevant vendor)
- Issues that are already publicly known and do not demonstrate any new impact or risk
3. How to Report a Vulnerability
If you discover a potential cybersecurity vulnerability in a TiMOTION product, please submit your report to our dedicated security email address, security@timotion.com
All reports submitted through this official channel are received, recorded, and tracked in our internal security management system. Each report is assigned a unique tracking number for follow-up and resolution.
Availability:
24/7 — Reports can be submitted at any time.
This reporting channel is intended for technical vulnerability reports, cybersecurity issues affecting TiMOTION products, and security incident notifications.
4. Information to Include
To help us understand, reproduce, and assess the reported vulnerability, please provide as much of the following information as possible:
4-1. Product Information
- Market segment
- Product type
- Part number
- Specification code
- Serial number
- Firmware version and/or software version, if applicable
Product identification information can generally be found on the product label. Firmware and software version information may be available through the applicable software interface.
4-2. Vulnerability Description and Reproduction Steps
Please provide a clear description of the vulnerability, including step-by-step instructions on how to reproduce the issue.
4-3. CVE ID (if applicable)
If the vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID, please provide it. Otherwise, this field may be left blank.
e.g. CVE-2025-1234
4-4. CVSS Vector (if applicable)
Please provide the applicable Common Vulnerability Scoring System (CVSS) vector string, if available. A complete vector string may be generated using the official CVSS calculator.
e.g. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
4-5. Public Disclosure or Active Exploitation
Please let us know if the vulnerability has been publicly discussed or if there is evidence that it is being actively exploited.
5. Handling Process
Once a vulnerability report is submitted, TiMOTION follows a structured process to review, assess, and address the reported issue. We will communicate with the reporter as appropriate throughout the process.
Stage
- Preliminary acknowledgement
- Formal receipt
- Status updates
- Resolution targets
- Verification and closure
TiMOTION assesses the severity of reported vulnerabilities using CVSS v3.1, together with the specific context of the issue. This may include factors such as attack complexity, exposure of the affected function, and any evidence of active exploitation.
If you disagree with our severity assessment, you may request a review. The case will be escalated to the TiMOTION Product Security Incident Response Team (hereinafter referred to as “PSIRT”) for further review.
6. Remediation, Advisories and Coordinated Disclosure
When a vulnerability is confirmed and remediation is appropriate, TiMOTION may release fixes through firmware, software, or application updates. Relevant security information may also be published on the TiMOTION Security Advisories page, where appropriate.
To support a coordinated disclosure process and allow sufficient time for remediation, we kindly ask reporters to refrain from publicly disclosing a reported vulnerability until a fix is available or 90 days have passed since TiMOTION formally received the report, whichever comes first.
If additional time is needed, extensions may be granted upon request, particularly when coordination with third parties is required.
In cases where a vulnerability is being actively exploited, TiMOTION may disclose relevant information before a complete fix is available to help protect affected users.
7. Safe Harbor
TiMOTION supports and encourages good-faith security research on products within the scope of this policy. TiMOTION does not intend to pursue legal action against researchers who conduct security research in good faith and in accordance with is this policy.
- Use only your own accounts, devices, and data. Do not access, modify, or delete information belonging to others.
- Stop testing immediately if unintended impact occurs and notify TiMOTION as soon as possible.
- Collect only the minimum information necessary to demonstrate the vulnerability.
- Respect individual privacy. Any personal data encountered during testing should be deleted after submitting your report.
By following these guidelines, you can help us improve the security of our products while minimizing potential risks to users and systems.
8. Recognition
With the reporter’s consent, TiMOTION may recognize the reporter by their name or preferred handle in the relevant security advisory. Recognition applies to valid reports regardless of the reporting channel used.
9. Confidentiality and Information Sharing
TiMOTION treats all reports, reporter identities and related communications as confidential. We will not publicly disclose a reporter’s identity or share it with third parties without the reporter’s consent, unless required by applicable law.
When necessary to investigate or resolve a vulnerability, relevant information may be shared confidentially with affected component or platform suppliers, PSIRT, recognized coordination partners, or competent authorities, in accordance with applicable laws and regulations, including Regulation (EU) 2024/2847.
10. Statutory Reporting under the CRA
If a vulnerability affecting a TiMOTION product with digital elements is actively exploited, or if a severe security incident occurs, you are encouraged to report the issue to TiMOTION following Section 3. How to Report a Vulnerability and 4. Information to Include sections of this policy.
Upon receiving such a report, TiMOTION will assess its applicable reporting obligations under the CRA. Where notification is required, TiMOTION will notify the European Union Agency for Cybersecurity (ENISA) through the Single Reporting Platform within the applicable statutory timeframes:
- Early warning: within 24 hours of becoming aware of the issue
- Full notification: within 72 hours
- Final report: when remediation is available or the incident has been resolved
If users need to take action to reduce or mitigate a security risk, TiMOTION will inform affected users without undue delay, in accordance with Article 14(8) of the CRA.
11. Support Period
TiMOTION provides security updates for products with digital elements throughout the applicable support period. The applicable support period is determined in accordance with applicable legal requirements, taking into account the nature of the product, its intended purpose, and its expected lifetime.
12. Policy Availability
This policy will be published on the TiMOTION website and made available throughout the applicable period required by law. Questions regarding this policy can be sent to security@timotion.com.