White KNX glass push-button from the eTR series, wall-mounted in front of a modern officeWhite KNX glass push-button from the eTR series, wall-mounted in front of a modern office

Cybersecurity of our Products

Product safety and vulnerability reporting

Our sensors, actuators and control systems are used in buildings that are expected to function reliably for decades. This means we take safety issues seriously – both during development and thereafter, throughout the entire service life of our products.

If you notice anything in an Elsner product that could be a security issue, please report it to us: by email to security@elsner-elektronik.de or via the reporting form on this page. Both methods reach the same team. We investigate every report and will confirm receipt – even if you are not sure whether it is actually a vulnerability.

Further down, you will also find an overview of the security vulnerabilities we have already rectified, specifying the affected devices and the firmware or software version that addresses the vulnerability.

Provide notification by email to security@elsner-elektronik.de
Vulnerability report

Information on the procedure

What we need from you

To help us process your report quickly, please provide:

  • the product concerned, including the item number and, if known, the firmware or application version
  • a description of the vulnerability and its potential impact
  • the steps required to reproduce the behaviour
  • your contact details in case we need to get in touch

We welcome reports in either German or English. Even an incomplete report is better than none at all. Please do get in touch rather than leaving the matter unresolved.

How we proceed

Confirmation of receipt within three working days. You will then know that your report has been received and is being processed.

Initial assessment within ten working days. We will let you know whether we have been able to reproduce the behaviour and how we assess it.

Ongoing updates. Whilst the issue is being resolved, we will keep you informed of the progress.

Publication following resolution. We publish details of resolved vulnerabilities in this section of our website so that operators of our devices can take action.

Credits on request. If you wish, we will credit you as the discoverer in the publication. If you prefer to remain anonymous, we will respect that too.

Please allow us time to rectify the issue before making any details public. As a guideline, we suggest 90 days from the date of your report. If a vulnerability is being actively exploited or if the fix takes longer, we will discuss the timing with you.

What we ask of you

To ensure that a well-intentioned test does not cause any harm:

  • Please only carry out tests on devices and systems that you own or for which you have explicit permission.
  • Do not access, alter or delete other people’s data.
  • Refrain from denial-of-service tests, social engineering, phishing and physical attacks on our premises or staff.
  • Do not disclose any details until you have consulted with us.

If you adhere to these rules, we will regard your report as a contribution to the security of our products and will not take any legal action against you. We make this commitment on our own behalf. We cannot speak on behalf of third parties or regarding decisions made by law enforcement agencies.

No bug bounty programme

We do not currently pay rewards for vulnerability reports. What we do offer is a thorough investigation, reliable feedback and, upon request, recognition as the discoverer.

Vulnerability report

Information on the procedure

If you believe you have found a security vulnerability in an Elsner Elektronik product, firmware, app or online service, please tell us.

Contact: security@elsner-elektronik.de (security reports only, for product support please use our regular service channels).

Please include the affected product and article number, the firmware or application version if known, a description of the issue and its possible impact, the steps to reproduce it, and how we can reach you. German and English are both fine.

What happens next: we acknowledge receipt within three working days, give you an initial assessment within ten working days, keep you informed while we work on a fix, and publish fixed vulnerabilities in this section of our website. We are happy to credit you by name, or to keep your report anonymous if you prefer.

Please test only on equipment you own or are explicitly authorised to test, do not access, modify or delete data belonging to others, avoid denial-of-service testing, social engineering and physical attacks, and give us time to fix the issue before disclosing details. 90 days from your report is our suggested guideline. If you follow these rules we will treat your report as a contribution to product security and will not pursue legal action against you. This undertaking is given on our own behalf. We cannot speak for third-party claims or for decisions taken by prosecuting authorities.

We do not currently operate a bug bounty programme.

Expert answers to your questions

How to get in touch with the right person

The email address security@elsner-elektronnik.de and the reporting form are intended solely for reporting security vulnerabilities.
For enquiries regarding orders, please contact info@elsner-elektronik.de.
You can contact our technical support team at service@elsner-elektronik.de.

Security Advisories

Information on security vulnerabilities that have been rectified

We are currently not aware of any security vulnerabilities that have been rectified and require publication. New entries will appear here.

Publication dateProductDescriptionSeverity Fixed from versionRecommendation for action