Vulnerability Disclosure Policy

Orbbec takes the security of our products, software, services, and users seriously. We value the contributions of security researchers and members of the security community who help us identify potential vulnerabilities and improve the security of our products and services.

If you believe you have discovered a security vulnerability affecting an Orbbec product or service, we encourage you to report it to us responsibly in accordance with this Vulnerability Disclosure Policy.

1. Scope

This policy applies to security vulnerabilities related to Orbbec products and services, including, where applicable:

  • Orbbec 3D cameras and LiDAR products

  • Device firmware

  • Orbbec SDKs, drivers, APIs, and related software

  • Orbbec applications and software tools

  • Orbbec-operated websites and online services

  • Other software or systems developed and maintained by Orbbec

Security issues involving third-party products, services, or components that are not controlled or maintained by Orbbec may fall outside the scope of this policy.

2. Reporting a Vulnerability

If you believe you have identified a security vulnerability, please report it privately to:

Email: eddie.huang@orbbec.com    Form:https://www.orbbec.com/vulnerability-submission/

To help us investigate the issue efficiently, please include as much relevant information as possible, such as:

  • A description of the vulnerability and its potential security impact

  • The affected product, model, service, or software

  • Firmware, SDK, software, or application version, if applicable

  • The URL or affected endpoint, if applicable

  • Detailed steps to reproduce the issue

  • Proof-of-concept code, screenshots, logs, or other supporting information, where appropriate

  • Any suggested remediation or mitigation

  • Your contact information for follow-up

Please do not include unnecessary personal information, confidential customer data, or other sensitive information in your report.

3. Responsible Security Research

When conducting security research involving Orbbec products or services, please:

  • Conduct testing only on devices, accounts, and systems that you own or are explicitly authorized to test.

  • Make a good-faith effort to avoid privacy violations, data loss, service disruption, or degradation of Orbbec systems or services.

  • Access only the information necessary to demonstrate the vulnerability.

  • Do not modify, delete, download, or retain data belonging to other users.

  • Do not perform denial-of-service or resource-exhaustion attacks.

  • Do not use social engineering, phishing, physical attacks, or other methods targeting Orbbec employees, customers, partners, or users.

  • Do not use a vulnerability for commercial exploitation or any unlawful purpose.

  • Report vulnerabilities to Orbbec promptly and allow us a reasonable period of time to investigate and address the issue before making any information publicly available.

If you inadvertently access sensitive or personal information during your research, please stop testing, do not retain or distribute the information, and notify us immediately.

4. Vulnerability Handling Process

After receiving a vulnerability report, Orbbec will generally follow the process below:

Step 1 — Acknowledgment
We review the submitted report and confirm receipt.

Step 2 — Verification and Assessment
Our security and technical teams reproduce the reported issue where possible and evaluate its severity, exploitability, affected products, and potential impact.

Step 3 — Remediation
Where a vulnerability is confirmed, the relevant teams develop an appropriate fix or mitigation.

Step 4 — Validation
The remediation is tested to verify that the vulnerability has been addressed and that the fix does not introduce significant unintended issues.

Step 5 — Release
Where appropriate, Orbbec may provide a firmware update, SDK or software update, service-side remediation, security advisory, mitigation guidance, or other corrective action.

Step 6 — Follow-up
Where contact information has been provided, we may notify the reporter of the investigation status or resolution.

We aim to acknowledge valid vulnerability reports within 3 business days and provide an initial assessment within 7 business days, where reasonably possible.

The time required to fully remediate a vulnerability may vary depending on its severity, complexity, affected products, required testing, hardware dependencies, supply-chain considerations, and other technical factors.

5. Vulnerability Severity

Orbbec evaluates reported vulnerabilities based on factors including:

  • Technical impact

  • Exploitability

  • Required privileges or user interaction

  • Scope of affected products or users

  • Potential impact on confidentiality, integrity, and availability

  • Availability of mitigations

  • Real-world attack feasibility

Where appropriate, Orbbec may reference industry-standard vulnerability assessment frameworks such as the Common Vulnerability Scoring System (CVSS).

Vulnerabilities may generally be categorized as Critical, High, Medium, or Low severity based on the overall security impact and risk.

6. Reports That May Not Qualify as Security Vulnerabilities

The following issues may generally be considered outside the scope of this policy unless they demonstrate a meaningful security impact:

  • General product defects or functional bugs without security impact

  • Reports that cannot be reproduced and contain insufficient technical information

  • Automated scanner reports without evidence of an exploitable vulnerability

  • Missing security headers without a demonstrated security impact

  • Self-XSS or issues requiring a user to execute code against themselves

  • Clickjacking on pages that do not contain sensitive actions

  • Open redirects without additional demonstrated security impact

  • Publicly available information or non-sensitive information disclosure

  • Rate-limit observations without a demonstrated security impact

  • Issues affecting unsupported or end-of-life products or software

  • Vulnerabilities that have already been reported and are being addressed

  • Vulnerabilities already publicly disclosed or already known to Orbbec

  • Vulnerabilities exclusively affecting third-party products or services outside Orbbec’s control

Orbbec will determine the applicability, severity, and validity of each report based on the specific circumstances.

7. Coordinated Disclosure

We appreciate researchers giving Orbbec a reasonable opportunity to investigate and remediate reported vulnerabilities before public disclosure.

Please do not publicly disclose vulnerability details, proof-of-concept code, exploitation methods, or other information that could increase security risk until Orbbec has completed its investigation and appropriate remediation has been made available, or until a disclosure timeline has been mutually coordinated.

For vulnerabilities with significant potential impact, Orbbec may issue a security advisory or other public notification where appropriate.

8. Recognition and Rewards

Orbbec appreciates the efforts of security researchers who responsibly disclose vulnerabilities and help improve the security of our products and services.

Unless separately announced by Orbbec, this Vulnerability Disclosure Policy does not constitute a bug bounty program, and submitting a vulnerability report does not create an entitlement to financial compensation or other rewards.

Any recognition or reward, if provided, will be determined by Orbbec at its sole discretion.

9. Confidentiality and Use of Submitted Information

Information submitted to Orbbec under this policy may be shared internally with relevant security, engineering, product, legal, and other teams as necessary to investigate and remediate the reported issue.

Orbbec may also work with relevant suppliers, technology partners, or other affected parties where necessary to resolve a vulnerability.

By submitting a report, you acknowledge that Orbbec may use the information you provide for security investigation, remediation, product improvement, and related purposes.

10. Policy Updates

Orbbec may update this Vulnerability Disclosure Policy from time to time to reflect changes in our products, services, security practices, or applicable requirements.

Please refer to this page for the latest version of the policy.

Last Updated: August 2026

Stay updated

Be the first to learn about our new
products and updates.