Skip to main content general.skipToSearch general.skipToNavigation
Product Security

Vulnerability Disclosure

Responsible reporting helps protect connected lighting systems, the people who use them and the environments they support. Hytronik connected products use Koolmesh wireless control technologies, so potential security vulnerabilities affecting Koolmesh-enabled products should be submitted through the official Koolmesh Vulnerability Disclosure Program.

Three clear steps.

Follow the official process so the Koolmesh security team receives the information needed to validate and investigate the issue efficiently.

  1. 01

    Confirm the scope

    Review the official policy before carrying out research or testing. It defines the included products, systems and exclusions.

  2. 02

    Document the issue

    Provide a clear vulnerability description, affected product family, model and firmware version, reproduction steps and any available proof-of-concept or technical logs.

  3. 03

    Report responsibly

    Email the details to Security@koolmesh.com and allow the coordinated remediation process to take place before any public disclosure.

Useful information, without the noise.

A concise report helps the security team reproduce the issue and assess its impact. The official Koolmesh policy remains the complete source for scope, safe-harbour conditions and prohibited activities.

Include in your report

  • Detailed description of the vulnerability
  • Affected product family, model and firmware version
  • Step-by-step reproduction method
  • Proof-of-concept, screenshots or logs if available
  • Contact information for follow-up communication

Research boundaries

  • No large-scale scanning, brute-force or DoS / DDoS testing
  • No unauthorised access to company or customer systems
  • No social engineering, phishing or privacy data collection
  • No physical damage or testing beyond normal installation
  • No public disclosure before coordinated remediation