MOBA Product Security Incident Response Team
Central point of contact for reporting security vulnerabilities in MOBA products and services.
The MOBA PSIRT coordinates the receipt, investigation and public disclosure of security vulnerabilities affecting MOBA Mobile Automation products, solutions and services. We work with security researchers, customers and partners to resolve reported issues and provide timely information to users.
Â
We are committed to transparent and responsible vulnerability management in accordance with ISO/IEC 29147 and the EU Cyber Resilience Act. This page is the single point of contact for security issues in MOBA products under the Cyber Resilience Act (Regulation (EU) 2024/2847).
Report a Vulnerability
Use this form to report MOBA Mobile Automation product vulnerabilities to the MOBA PSIRT.
In scope are serious design or implementation issues affecting confidentiality, integrity, or user security, for example:
- Undisclosed device access methods
- Hardcoded or undocumented account credentials
- Undocumented traffic diversion
- Cross-site scripting
- Cross-site request forgery
- Mixed-content scripts
- Authentication or authorization flaws
- Server-side code execution bugs
- Bypass of security feature (Bypass of AV/IPS engine)
MOBA considers such product behaviors to be serious vulnerabilities and handles disclosure under the terms of the MOBA Security Vulnerability Policy.
What helps us assess it
- Exact product name and version
- Preconditions: access via CAN, radio, USB or network?
- Evidence that demonstrates the impact
- Your severity estimate, ideally as a CVSS vector
How we handle your report
1. Receipt
We assign your report a case number and forward it directly to our PSIRT.
2. Acknowledgement
Within 3 business days, we confirm receipt and provide a named contact.
3. Assessment
Within 10 business days: affected products, CVSS severity, next steps.
4. Remediation
We work on a fix and update you on our progress at least every 30 days.
5. Disclosure
Once a fix is available, we publish a security advisory in coordination with you. We aim to do so within 90 days of receiving your report.
Reporting obligations and sharing
Under Art. 14 of the Cyber Resilience Act, we must report actively exploited vulnerabilities and severe security incidents to the competent CSIRT via ENISA’s Single Reporting Platform. As a rule, this does not require your personal details.
Â
If the vulnerability is in a supplier component or open-source software, we also inform its manufacturer or maintainer.
Â
We only share your identity with your consent or where the law requires it. You may also report vulnerabilities voluntarily and directly to a CSIRT. In Germany this is the BSI.