Security Policy
Last updated: 2026-09-15
WideWired takes the security of its services and clients seriously. This page is the entry point for reporting suspected vulnerabilities. The machine-readable version of this policy is published at /.well-known/security.txt per RFC 9116.
1. Reporting a Vulnerability
Please report suspected vulnerabilities through one of the channels below.
Please do not disclose security matters in public venues such as social media or public forums. Public reports will be redirected to the address above before triage begins.
2. Sensitive Material
Please keep the initial report to the minimum detail needed for triage and avoid sending secrets, private keys, customer data, or exploit payloads that are not required to understand the issue. If sensitive supporting material is necessary, contact us first at security@widewired.com so we can arrange an appropriate secure channel.
3. What to Include
A useful report contains:
- A short summary of the issue and the impact you believe it has.
- Reproduction steps against your own test account or a clean environment.
- The affected surface (a registered website, admin site, API, or the
wwnetclient) and the version, if known. - A proof of concept: the minimum payload, request, or script sufficient to verify the finding. Please do not exfiltrate data belonging to other users.
- Any suggested mitigation, if you have one.
4. Disclosure Window
We follow coordinated disclosure. By default we ask reporters to keep the finding confidential until a fix is shipped, or for up to 90 days from the acknowledgement date, whichever comes first. Extensions are negotiated by email.
5. Response SLA
| Stage | Target |
|---|---|
| First acknowledgement | within 72 hours |
| Triage and severity assignment | within 7 days |
| Fix for critical severity | within 30 days |
| Fix for high severity | within 60 days |
| Fix for medium or low severity | within 90 days |
Severity is decided per the matrix in our internal vulnerability disclosure policy. Critical covers RCE on backend services, fleet private-key compromise, account takeover, and billing bypass.
6. Scope
In scope.
- Registered Global public website and API hosts:
dev.widewired.com,dev-api.widewired.com,www.widewired.com, andwww-api.widewired.com. - Registered China public website and API hosts:
dev.widewired.com.cn,dev-api.widewired.com.cn,www.widewired.com.cn, andwww-api.widewired.com.cn. - The
wwnetclient, its self-update mechanism, and the OTA artifact and manifest signing chain.
Out of scope.
- Third-party dependencies (Go modules, npm packages): please report upstream.
- Third-party payment processors (Stripe, Alipay): please report to the processor.
- Social engineering or phishing against WideWired staff.
- Physical security or office intrusion.
- Denial of service and volumetric or stress testing.
- Findings already listed as known limitations in our published security documents.
- Metric endpoints that require a token and are documented as such.
7. Safe Harbor
We will not pursue legal action or technical retaliation against researchers who act in good faith and within this policy. Good faith means:
- Testing limited to your own accounts or accounts you control.
- No denial of service or volumetric testing against production.
- No reading, modifying, or deleting data belonging to other users.
- No public disclosure before a fix ships or the 90 day window elapses.
- No demand for payment in exchange for withholding a report.
A report that breaches any of the above falls outside safe harbor.
8. Recognition
After a fix is shipped, we credit reporters (with their consent) on our Hall of Fame. Anonymous acknowledgement is available on request.
9. Contact
Security reports: security@widewired.com. For non-security questions, see the Contact page.
安全策略
最近更新:2026-09-15
网连网络(WideWired)十分重视服务与客户端的安全。本页面是上报疑似漏洞的入口。本策略的机读版本依据 RFC 9116 发布在 /.well-known/security.txt。
1. 上报漏洞
请通过下列任一渠道上报疑似漏洞。
请勿在社交媒体、公开论坛等公开场合发布安全相关内容。公开上报会被引导至上述渠道后再进行分诊。
2. 敏感材料
初次上报请只包含分诊所需的最少信息,避免发送不必要的 secret、私钥、客户数据或利用载荷。确需补充敏感材料时,请先通过 security@widewired.com 联系我们,以便安排合适的安全通道。
3. 报告内容建议
一份有效的上报通常包含:
- 问题摘要,以及你认为造成的影响。
- 在你自己的测试账号或干净环境中可复现的步骤。
- 受影响的表面(已登记的网站、管理站、API 或
wwnet客户端)以及版本号(如可提供)。 - 概念验证:足以验证该发现的最小载荷、请求或脚本。请不要导出他人数据。
- 如有可行的缓解建议,欢迎一并提供。
4. 披露窗口
我们采用协同披露。默认请求上报者在修复发布前、或自确认日起 90 天内(以先到为准)对该发现保密;可通过邮件协商延期。
5. 响应 SLA
| 阶段 | 目标 |
|---|---|
| 首次确认 | 72 小时内 |
| 分诊及严重性评级 | 7 天内 |
| 严重级修复 | 30 天内 |
| 高级修复 | 60 天内 |
| 中、低级修复 | 90 天内 |
严重性按我们内部漏洞披露规范中的矩阵判定。严重级覆盖:后端服务上的 RCE、fleet 私钥泄露、任意账号接管,以及计费旁路。
6. 范围
纳入范围。
- 已登记的 Global 公开网站和 API:
dev.widewired.com、dev-api.widewired.com、www.widewired.com、www-api.widewired.com。 - 已登记的 China 公开网站和 API:
dev.widewired.com.cn、dev-api.widewired.com.cn、www.widewired.com.cn、www-api.widewired.com.cn。 wwnet客户端、自更新机制,以及 OTA 制品和 manifest 签名链。
不在范围。
- 第三方依赖(Go 模块、npm 包):请直接上报至上游。
- 第三方支付通道(Stripe、Alipay):请上报至通道方。
- 针对网连网络员工的社工或钓鱼。
- 物理安全或办公室入侵。
- 拒绝服务及大流量、压力测试。
- 已在我们公开的安全文档中列为已知限制的发现。
- 需要 token、且已在文档中声明的 metric 端点。
7. 安全港承诺
对于在本策略框架内、出于善意进行研究的安全研究员,我们承诺不提起诉讼,也不进行技术对抗。善意的边界包括:
- 测试仅限于你本人或你控制的账号。
- 不对生产环境进行拒绝服务或大流量测试。
- 不读取、修改、删除其他用户的数据。
- 在修复发布前或 90 天披露窗口到期前不公开披露。
- 不以撤回报告为条件索取报酬。
任一项不满足,即不在安全港范围内。
8. 致谢
修复发布后,经报告者授权,我们会将其登记在 致谢名录。也可应请求匿名致谢。
9. 联系方式
安全相关:security@widewired.com。非安全类问题请前往 联系我们 页面。