1. Purpose and Commitment
Our Promise
TiMOTION (Dongguan TiMOTION Transmission Technology Co., Ltd.) is a leading manufacturer of electric linear actuator systems. We are committed to the security and resilience of our products and to continuously improving the potential vulnerabilities.
This Vulnerability Disclosure Policy (VDP) explains how security researchers, customers, and business partners, can report security vulnerabilities to TiMOTION, and how we assess, address, and communicate such issues.
This policy applies to TiMOTION products with digital elements, including smart linear actuators such as the T-Smart series, electric lifting columns, control boxes, related accessories and miscellaneous items such as mobile application, placed on the European Union market within the scope of Regulation (EU) 2024/2847 (Cyber Resilience Act, hereinafter referred to as “CRA”).
Our Commitment
Product security is a shared responsibility. We welcome vulnerability reports submitted in good faith and are committed to handling them responsibly, transparently, and collaboratively. Your contributions help us strengthen the security and resilience of our products and better protect our customers and partners.
2. Scope
What Are Covered?
We welcome reports of security vulnerabilities affecting TiMOTION hardware products, firmware, and mobile applications that are within their support period (see Section 11). Reports concerning any firmware or software version released during the support period are accepted. While testing against the latest available version is encouraged, it is not required.
What Are Excluded?
The following are excluded by this vulnerability reporting process:
- Social engineering targeting TiMOTION employees or dealers
- Physical attacks against TiMOTION products or related services
- Denial-of-service (DoS) or resource-exhaustion testing
- Spam or mass credential attacks
- Vulnerabilities in third-party applications or services not maintained by TiMOTION (please report these directly to the relevant vendor)
- Issues that are already publicly known and do not demonstrate any new impact or risk
3. How to Report a Vulnerability
If you discover a potential cybersecurity vulnerability in a TiMOTION product, please submit your report to our dedicated security email address, security@timotioncn.com
All reports submitted through this official channel are formally received, recorded, and tracked in our internal security management system. Each report is assigned an individual tracking number for follow-up and handling.
Availability:
24/7 — Reports can be submitted at any time.
This reporting channel is intended for technical vulnerability reports, cybersecurity issues affecting TiMOTION products, and security incident notifications.
4. Information to Include
To help us understand, reproduce, and assess the reported vulnerability, please provide as much of the following information as possible:
- Market Segment
- Product type, Part No, Spec Code, Serial No
*Product identification information can usually be found on the product label.
- Firmware Version, Software Version
*This information may be available in the relevant software service page.
- Vulnerability Description and Reproduction Steps
*Please provide a clear description of the vulnerability, including step-by-step instructions on how to reproduce the issue.
- CVE ID/ Common Vulnerabilities and Exposures record ID
*If the vulnerability has been assigned a CVE ID, please provide it accordingly. Otherwise, this field may be left blank.
e.g. CVE-2025-1234
- Common Vulnerability Scoring System (CVSS) Vector
*Fill in the corresponding CVSS vector string, if any. The complete vector string can be generated using the official CVSS calculator.
e.g. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Public Disclosure or Active Exploitation
*Let us know if there is any open discussion, or evidence that the vulnerability is being actively exploited,
5. Handling Process and Timeframes
Once a vulnerability report is submitted, TiMOTION follows a structured process to review, assess, and address the reported issue. We aim to keep reporters informed along the way.
Stage
- Preliminary acknowledgement
- Formal receipt
- Status updates
- Resolution targets
- Verification and closure
TiMOTION assesses the severity of reported vulnerabilities using CVSS v3.1, together with the specific context of the issue. This may include factors such as attack complexity, exposure of the affected function, and any evidence of active exploitation.
If you disagree with our severity assessment, you may request a review. The case will be escalated to the TiMOTION Product Security Incident Response Team (hereinafter referred to as “PSIRT”), which will review the assessment within 5 work days.
6. Remediation, Advisories and Coordinated Disclosure
When vulnerability is addressed, TiMOTION may release fixes through firmware, software, or application updates. Relevant security information will also be published on the TiMOTION Security Advisories page, where appropriate.
To support a coordinated disclosure process and allow sufficient time for remediation, we kindly ask reporters to refrain from publicly disclosing a reported vulnerability until a fix is available or 90 days have passed since TiMOTION formally received the report, whichever comes first.
If additional time is needed, extensions may be granted upon request, particularly when coordination with third parties is required.
In cases where vulnerability is being actively exploited, TiMOTION may disclose relevant information before a complete fix is available to help protect affected users.
7. Safe Harbor
TiMOTION supports and encourages good-faith security research on products within the scope of this policy. When conducted responsibly and in accordance with the requirements below, such research is considered authorized under this policy.
- Use only your own accounts, devices, and data. Do not access, modify, or delete information belonging to others.
- Stop testing immediately if unintended impact occurs and notify TiMOTION as soon as possible.
- Collect only the minimum information necessary to demonstrate the vulnerability.
- Respect individual privacy. Any personal data encountered during testing should be deleted after submitting your report.
By following these guidelines, you can help us improve the security of our products while minimizing potential risks to users and systems.
8. Recognition
With the reporter’s consent, TiMOTION is pleased to recognize the contributed reporter by their name or preferred handle ID in the relevant security advisory. Recognition applies to valid reports regardless of the reporting channel used.
9. Confidentiality and Information Sharing
TiMOTION treats all reports, reporter identities and related communications as confidential. We will not publicly disclose a reporter’s or share it with third parties without the reporter’s consent, unless required by applicable law.
When necessary to investigate or resolve a vulnerability, relevant information may be shared confidentially with affected component or platform suppliers, PSIRT, recognized coordination partners, or competent authorities, in accordance with applicable laws and regulations, including Regulation (EU) 2024/2847.
10. Statutory Reporting under the CRA
If a vulnerability affecting a TiMOTION product with digital elements is actively exploited, or if a severe security incident occurs, you are encouraged to report the issue to TiMOTION following the How to Report a Vulnerability and Information to Include sections of this policy.
Upon receiving such a report, TiMOTION will notify the European Union Agency for Cybersecurity (ENISA) through the Single Reporting Platform. Where applicable, notifications will be made within the required timeframes:
- Early warning: within 24 hours of becoming aware of the issue
- Full notification: within 72 hours
- Final report: when remediation is available or the incident has been resolved
If users need to take action to reduce or mitigate a security risk, TiMOTION will inform affected users without undue delay, in accordance with Article 10(5) of the CRA.
11. Support Period
TiMOTION provides security updates for its products with digital elements throughout the applicable support period. The support period is aligned with the product warranty period and begins after the last unit of the relevant model is placed on the market.
Depending on the product, the support period may be less than five years. The applicable support period is determined based on the product’s intended purpose and expected lifetime.
12. Policy Availability and Accessibility
This policy is published on the TiMOTION website and remains permanently available. Questions about this policy can be sent to security@timotioncn.com.