
Product Safety / CRA
Cyber Resilience Act - Report a Security Incident
Please report security-related incidents within 24 hours of discovery in accordance with Article 14 of the Cyber Resilience Act (CRA).
Each report will be reviewed internally and documented in a traceable manner.
Responsible Management of Security Incident Reports
Reports of potential vulnerabilities are reviewed, technically evaluated, and, where required, coordinated with the relevant internal or external specialists.
Confidentiality
We handle your report with care and discretion. Information is disclosed only to those persons who are required to investigate and resolve the reported issue.
Carefully Evaluated
We assess affected products, hardware and software versions, and evaluate potential impacts on product security and resilience.
Feedback
If you provide contact details, we will confirm receipt of your report and, where appropriate, keep you informed about the further handling of the matter.
What We Need From You
The more detailed your information, the faster we can assess the incident and take appropriate action.
- Affected EXAKT product/device
- Hardware variant and firmware/software version
- Description of the potential security vulnerability
- Steps to reproduce the issue
- Potential impact
- Screenshots, logs, or other technical information
Please do not submit passwords or unnecessary personal data.
CRA Notice:Security incidents must be reported within 24 hours of discovery (Article 14 of the Cyber Resilience Act).
Responsible Security Research
We welcome reports from security researchers, customers, and business partners that contribute to enhancing the security of our products and digital components.
- Conduct testing only on systems and devices for which you are explicitly authorized to perform security assessments.
- Refrain from any activity that may disrupt operations or adversely affect the systems of other users.
- Do not access, modify, disclose, or delete data belonging to third parties.
- Do not exploit identified vulnerabilities beyond the extent necessary to demonstrate their existence and potential impact.
- Please refrain from publicly disclosing technical details until we have been given a reasonable opportunity to investigate and remediate the reported issue.
Other requests?
This channel is dedicated solely to the reporting of potential security vulnerabilities affecting EXAKT products, software, firmware, and related digital components.
It is not intended for general technical support, service requests, or product inquiries. For such matters, please contact EXAKT through the established support channels.
Email: info@exakt.de