Security Vulnerability Reporting

Pexar has designated the contact details on this page as our single point of contact for reporting product vulnerabilities, in accordance with Regulation (EU) 2024/2847 (the EU Cyber Resilience Act).

If you discover a security vulnerability in one of our products or services, you can report it to us by sending an email to security@pexar.com. Reports may be submitted anonymously.

Please include the following information:

  • Name of product, model number, firmware or software version
  • Description of the vulnerability
  • Reproduction steps of the vulnerability
  • Suggestions for fixes or mitigation (if any)

We will contact you within 3 business days of receiving your report to confirm receipt.

We will report on the vulnerability remediation process every two to three weeks until the vulnerability is solved.

Scope

In scope: Pexar digital photo frames, docking stations, and their companion mobile apps, desktop software, and cloud services.

Out of scope — the following are not accepted under this policy:

  • Denial-of-service (DoS/DDoS) testing
  • Social engineering or phishing against Pexar staff or customers
  • Physical attacks against Pexar offices or personnel
  • Testing against third-party services we do not operate (e.g. our e-commerce platform provider)
  • Reports of missing security headers or best-practice deviations without demonstrable security impact

Safe Harbour

If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorised, we will work with you to understand and resolve the issue quickly, and Pexar will not pursue legal action against you.

If a third party initiates legal action against you in connection with activities conducted under this policy, we will make this authorisation known.

Note:

  • Vulnerability reports should be handled with care. False reports or malicious activities are prohibited
  • Vulnerability management is managed based on the life cycle of product/software versions. Pexar will manage the vulnerabilities of all products before the end of service and support (EOS).
  • To protect our users, Pexar will not disclose, discuss, or confirm any security issues until a full investigation has been completed and an update is available. We kindly ask reporting parties to keep vulnerabilities confidential and not share unresolved vulnerabilities with third parties or make them public until Pexar provides the related patch solution.
  • In order to better support customers in patch deployment and risk assessments, Pexar will simultaneously publish vulnerability patching status in Security Advisories below. It is recommended that you follow the update prompts to upgrade to a new product/software version or install the latest patches to reduce the risk of vulnerabilities.

Security Advisories

Once a reported vulnerability has been remediated, we publish the outcome here, following coordinated disclosure principles. Each advisory includes the affected products and versions, a summary of the issue, and the version in which it was fixed.

No advisories at this time.

We appreciate your contributions to improving security. The report will be taken seriously, and appropriate actions will be taken.