1. Our Commitment

Comba attaches high importance to product cybersecurity. We welcome and thank global security researchers for responsibly disclosing security risks and product vulnerabilities to us.

We commit to:

  • Provide safe harbor protection for security researchers who conduct good-faith and responsible vulnerability disclosure.
  • Respond to vulnerability reports in a timely manner and maintain transparent communication.
  • Verify and remediate security risks and release security updates where necessary.
  • Publicly acknowledge contributors in official security advisories upon the reporter’s consent.

 


 

2. Scope of Application

This Policy applies to external security researchers, partners, and users who report security risks affecting Comba products available on the EU market, including hardware, firmware, and remote network management systems.

 


 

3. Safe Harbor Statement

Safe Harbor

Comba will not initiate civil or criminal legal proceedings against security researchers who submit vulnerability reports in good faith, follow this Policy, avoid malicious exploitation, and do not publicly disclose vulnerabilities before remediation.

This protection does not apply to activities including blackmail, malicious intrusion, data theft, public disclosure before remediation, or other malicious actions.

 


 

4. Vulnerability Reporting Channels

Official Vulnerability Reporting Channels

Comba provides the following official security risk reporting channels, available 24 hours a day, 7 days a week.

 

Encrypted Email

Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

Purpose: For all vulnerability reports. This is the preferred channel for reporting sensitive vulnerabilities.

 

Dedicated Hotline

Phone: +34 910 618 108

Purpose: For reporting critical high-risk vulnerabilities and vulnerabilities under active exploitation.

 

Hardcopy Mail

Address: Calle Diego de León nº69, Escalera 1, 2A, 28006 Madrid – Spain

Purpose: Submission of formal written vulnerability reports and supporting materials.

 


 

5. Vulnerability Report Requirements

To help us verify and remediate vulnerabilities efficiently, please provide the following information whenever possible:

  1. Vulnerability name, CWE ID (if available), and CVE ID (if available)
  2. Affected product model numbers and firmware versions
  3. Detailed and reproducible vulnerability exploitation steps
  4. Proof of Concept (POC) code or demonstration video (if available)
  5. Vulnerability impact scope and risk assessment
  6. Contact information for follow-up communication (optional)

 


 

6. Vulnerability Handling Process & Timeline

Handling Process

Security Risk Report Receipt 

→ Acknowledgement 

→ Vulnerability Verification 

→ Risk Assessment 

→ Remediation & Testing 

→ Security Update Release 

→ Public Disclosure

 

Response Timeline

 


 

7. Security Advisories

Comba publishes security advisories to provide information about identified vulnerabilities and available security updates.

Each advisory includes:

  • Internal vulnerability ID and CVE ID (if applicable)
  • Affected product models and firmware versions
  • Vulnerability description, severity level, and impact scope
  • Security update version and download link
  • Recommended protection measures and temporary mitigation solutions

 


 

Back to Security Center >>