Vulnerabilities in Rommelag products, firmware, apps, and product-related services.
Report a security vulnerability
This is the single point of contact of Rommelag SE & Co. KG for reporting security vulnerabilities in our products and services. Thank you for helping us keep our users safe.
Before you report, please read our Coordinated Vulnerability Disclosure Policy. It describes what is in scope, the rules of engagement, our response times, and our safe harbour commitment for security researchers acting in good faith.
We acknowledge every report within 3 business days.
Active exploitation or an ongoing incident? Send your report to psirt@rommelag.com with the subject URGENT and state the evidence of active exploitation prominently at the top of your report.
How to reach us
We maintain a single point of contact for all vulnerability reports. The PSIRT mailbox reaches our Product Security Incident Response Team, which is responsible for vulnerabilities in the products we ship. Vulnerabilities in our own IT infrastructure and websites are handled by our Corporate Security Incident Response Team. If you are unsure which applies, write to the PSIRT mailbox – we route the report internally.
Vulnerabilities and incidents affecting our own IT infrastructure and websites.
Our contact details and this policy in machine-readable form.
Rommelag SE & Co. KG
Security Team
Talstraße 22-30
74429 Sulzbach-Laufen, Germany
Reports may be submitted in English or German. Anonymous reports are accepted; please note, however, that we can then neither ask follow-up questions nor inform you about the outcome.
Please note that e-mail is transmitted unencrypted.
Please do not use our general support channels, sales contacts, social media, or public issue trackers for vulnerability reports. Public disclosure before a fix is available puts our users at risk.
What your report should contain
The more precise your report, the faster we can reproduce and fix the issue. Useful information includes:
- the affected product, the exact version or firmware release, and the affected component;
- the configuration and environment in which you observed the issue;
- the vulnerability type (for example CWE class) and a technical description;
- a step-by-step description that allows us to reproduce the issue;
- proof of concept: request/response samples, log excerpts, screenshots, scripts, or a short video;
- your assessment of the impact and, if available, a CVSS v3.1 or v4.0 vector;
- the prerequisites for exploitation (network position, authentication, user interaction);
- whether the vulnerability is already publicly known or is being actively exploited;
- whether you have already reported it to another party (for example a CERT/CSIRT or a coordinator);
- your intended publication date, if any, and how you would like to be credited;
- contact details for follow-up questions.
Attachments such as proof of concept, scripts, log excerpts, screenshots, recordings, or a short video are welcome. Please do not send personal data or customer data beyond what is unavoidable for understanding the issue. For large files, contact us in advance at psirt@rommelag.com so that we can agree on a transfer method.
Credit and publication
We are happy to credit you in the advisory by name, pseudonym, organization, and link – exactly as you prefer. Please tell us in your report how you would like to be credited, or that you would rather not be named.
If you plan your own publication, please tell us the intended date. Our standard coordination window is 90 days; we will contact you if we need more time.
Handling of your data
We process the information you provide solely to handle your report, to communicate with you about security matters, and to meet our statutory obligations. Details are set out in section 10 of the CVD policy and in our privacy policy.