HD Hyundai Electric
Cybersecurity Center

HD Hyundai Electric has established a cybersecurity framework based on international security standards
to ensure the safe operation of its products and services. We have obtained global certifications including
ISO/IEC 27001, and manage security risks primarily through the CISO (Chief Information Security Officer)
organization.

  • Cybersecurity Center
  • Security Activity Notifier
  • Security Notice
  • Report Vulnerabilities

Introduction to Cybersecurity Services

  • Security Activity Notifier

    International security certifications (such as ISO/IEC 27001) and product security-related
    assessment results are disclosed.

    View Security Activity Notifier
  • Security Notice

    You can check security notices such as vulnerabilities (CVEs) found in products,
    affected products, patch files, or mitigation
    actions.

    View Security Notice
  • Vulnerability Report

    HD Hyundai Electric accepts product vulnerability reports in accordance with its Responsible Disclosure policy.

    View Vulnerability Report

FAQ

Cybersecurity FAQ

Q. Where can I find security notices or information on vulnerability patches?

We provide information on security vulnerability remediation status and security updates through the following sections.

※ The scope and timing of disclosure may vary depending on the severity of the vulnerability, product impact, and remediation status.

Q. What qualifies as a reportable item?

We accept reports regarding the following technical security vulnerabilities:

 

[In-Scope]

  • Cross-Site Scripting (XSS)
  • Injection vulnerabilities (e.g., SQL Injection)
  • Authentication/Authorization bypass
  • Exposure of sensitive information (e.g., personal data, authentication credentials)
  • Security vulnerabilities caused by server or product misconfiguration
  • Remote Code Execution (RCE)
  • Command Injection
  • Improper file access (e.g., Path Traversal)
  • Weak encryption or authentication methods
  • Exposure of critical authentication credentials (e.g., hardcoded accounts, passwords, or encryption keys)
  • Insecure updates or vulnerabilities in the update verification process
  • Denial of Service (DoS) vulnerabilities resulting from flawed product handling
  • Other security vulnerabilities affecting the confidentiality, integrity, or availability of the product


[Out-of-Scope]

  • Spam or phishing email reports
  • Social engineering attempts
  • General physical intrusion or access attempts
  • General Denial of Service (DoS/DDoS) attacks themselves
  • Simple security events unrelated to product vulnerabilities
  • Simple re-reports of publicly known vulnerabilities without new information or impact on the product

If you are unsure whether an issue falls within the scope, please submit a report anyway, we will review it and provide guidance.

Q. I’ve discovered a vulnerability; how do I report it?

We highly value reports from individuals who discover security vulnerabilities and accept vulnerability reports through the following channels.

 

1.  Website Submission: Please complete the reporting form on the Vulnerability Reporting Page.

2.  Email Submission: Please send your report to hde.cybersecurity@hd.com

 

  • PGP Encryption: If your report contains sensitive information, we recommend encrypting it using our PGP public key before sending it by email. (PGP Key and Usage Guide)

  • Recommended Information to Include: Detailed description of the vulnerability, reproduction steps, impact scope, and the environment in which it was discovered (browser, operating system, etc.).

  • Response Process: Reports are handled in the following order: Acknowledgment of Receipt → Internal Review → Remediation → Feedback to Reporter. An initial response will be provided within 7 business days of report submission.

  • Personal Data Handling: Personal information provided in a vulnerability report will be retained for two years after the purpose of processing has been fulfilled and will then be securely deleted.