Vulnerability Disclosure Policy
Orbbec takes the security of our products, software, services, and users seriously. We value the contributions of security researchers and members of the security community who help us identify potential vulnerabilities and improve the security of our products and services.
If you believe you have discovered a security vulnerability affecting an Orbbec product or service, we encourage you to report it to us responsibly in accordance with this Vulnerability Disclosure Policy.
1. Scope
This policy applies to security vulnerabilities related to Orbbec products and services, including, where applicable:
Orbbec 3D cameras and LiDAR products
Device firmware
Orbbec SDKs, drivers, APIs, and related software
Orbbec applications and software tools
Orbbec-operated websites and online services
Other software or systems developed and maintained by Orbbec
Security issues involving third-party products, services, or components that are not controlled or maintained by Orbbec may fall outside the scope of this policy.
2. Reporting a Vulnerability
If you believe you have identified a security vulnerability, please report it privately to:
Email: eddie.huang@orbbec.com Form:https://www.orbbec.com/vulnerability-submission/
To help us investigate the issue efficiently, please include as much relevant information as possible, such as:
A description of the vulnerability and its potential security impact
The affected product, model, service, or software
Firmware, SDK, software, or application version, if applicable
The URL or affected endpoint, if applicable
Detailed steps to reproduce the issue
Proof-of-concept code, screenshots, logs, or other supporting information, where appropriate
Any suggested remediation or mitigation
Your contact information for follow-up
Please do not include unnecessary personal information, confidential customer data, or other sensitive information in your report.
3. Responsible Security Research
When conducting security research involving Orbbec products or services, please:
Conduct testing only on devices, accounts, and systems that you own or are explicitly authorized to test.
Make a good-faith effort to avoid privacy violations, data loss, service disruption, or degradation of Orbbec systems or services.
Access only the information necessary to demonstrate the vulnerability.
Do not modify, delete, download, or retain data belonging to other users.
Do not perform denial-of-service or resource-exhaustion attacks.
Do not use social engineering, phishing, physical attacks, or other methods targeting Orbbec employees, customers, partners, or users.
Do not use a vulnerability for commercial exploitation or any unlawful purpose.
Report vulnerabilities to Orbbec promptly and allow us a reasonable period of time to investigate and address the issue before making any information publicly available.
If you inadvertently access sensitive or personal information during your research, please stop testing, do not retain or distribute the information, and notify us immediately.
4. Vulnerability Handling Process
After receiving a vulnerability report, Orbbec will generally follow the process below:
Step 1 — Acknowledgment
We review the submitted report and confirm receipt.
Step 2 — Verification and Assessment
Our security and technical teams reproduce the reported issue where possible and evaluate its severity, exploitability, affected products, and potential impact.
Step 3 — Remediation
Where a vulnerability is confirmed, the relevant teams develop an appropriate fix or mitigation.
Step 4 — Validation
The remediation is tested to verify that the vulnerability has been addressed and that the fix does not introduce significant unintended issues.
Step 5 — Release
Where appropriate, Orbbec may provide a firmware update, SDK or software update, service-side remediation, security advisory, mitigation guidance, or other corrective action.
Step 6 — Follow-up
Where contact information has been provided, we may notify the reporter of the investigation status or resolution.
We aim to acknowledge valid vulnerability reports within 3 business days and provide an initial assessment within 7 business days, where reasonably possible.
The time required to fully remediate a vulnerability may vary depending on its severity, complexity, affected products, required testing, hardware dependencies, supply-chain considerations, and other technical factors.
5. Vulnerability Severity
Orbbec evaluates reported vulnerabilities based on factors including:
Technical impact
Exploitability
Required privileges or user interaction
Scope of affected products or users
Potential impact on confidentiality, integrity, and availability
Availability of mitigations
Real-world attack feasibility
Where appropriate, Orbbec may reference industry-standard vulnerability assessment frameworks such as the Common Vulnerability Scoring System (CVSS).
Vulnerabilities may generally be categorized as Critical, High, Medium, or Low severity based on the overall security impact and risk.
6. Reports That May Not Qualify as Security Vulnerabilities
The following issues may generally be considered outside the scope of this policy unless they demonstrate a meaningful security impact:
General product defects or functional bugs without security impact
Reports that cannot be reproduced and contain insufficient technical information
Automated scanner reports without evidence of an exploitable vulnerability
Missing security headers without a demonstrated security impact
Self-XSS or issues requiring a user to execute code against themselves
Clickjacking on pages that do not contain sensitive actions
Open redirects without additional demonstrated security impact
Publicly available information or non-sensitive information disclosure
Rate-limit observations without a demonstrated security impact
Issues affecting unsupported or end-of-life products or software
Vulnerabilities that have already been reported and are being addressed
Vulnerabilities already publicly disclosed or already known to Orbbec
Vulnerabilities exclusively affecting third-party products or services outside Orbbec’s control
Orbbec will determine the applicability, severity, and validity of each report based on the specific circumstances.
7. Coordinated Disclosure
We appreciate researchers giving Orbbec a reasonable opportunity to investigate and remediate reported vulnerabilities before public disclosure.
Please do not publicly disclose vulnerability details, proof-of-concept code, exploitation methods, or other information that could increase security risk until Orbbec has completed its investigation and appropriate remediation has been made available, or until a disclosure timeline has been mutually coordinated.
For vulnerabilities with significant potential impact, Orbbec may issue a security advisory or other public notification where appropriate.
8. Recognition and Rewards
Orbbec appreciates the efforts of security researchers who responsibly disclose vulnerabilities and help improve the security of our products and services.
Unless separately announced by Orbbec, this Vulnerability Disclosure Policy does not constitute a bug bounty program, and submitting a vulnerability report does not create an entitlement to financial compensation or other rewards.
Any recognition or reward, if provided, will be determined by Orbbec at its sole discretion.
9. Confidentiality and Use of Submitted Information
Information submitted to Orbbec under this policy may be shared internally with relevant security, engineering, product, legal, and other teams as necessary to investigate and remediate the reported issue.
Orbbec may also work with relevant suppliers, technology partners, or other affected parties where necessary to resolve a vulnerability.
By submitting a report, you acknowledge that Orbbec may use the information you provide for security investigation, remediation, product improvement, and related purposes.
10. Policy Updates
Orbbec may update this Vulnerability Disclosure Policy from time to time to reflect changes in our products, services, security practices, or applicable requirements.
Please refer to this page for the latest version of the policy.
Last Updated: August 2026
