HD Hyundai Electric
Cybersecurity Center

HD Hyundai Electric has established a cybersecurity framework based on international security standards to ensure the safe operation of its products and services. We have obtained global certifications including ISO/IEC 27001, and manage security risks primarily through the CISO (Chief Information Security Officer) organization.

More

Introduction to Cybersecurity Services

  • Security Activity Notifier

    International security certifications (such as ISO/IEC 27001) and product security-related assessment results are disclosed.

    View Security Activity Notifier
  • Security Notice

    You can check security notices such as vulnerabilities (CVEs) found in products, affected products, patch files, or mitigation actions.

    View Security Notice
  • Vulnerability Report

    HD Hyundai Electric accepts product vulnerability reports in accordance with its Responsible Disclosure policy.

    View Vulnerability Report

FAQ

  • Q. Where can I find security notices or information on vulnerability patches?

    We provide information on security vulnerability remediation status and security updates through the following sections.

    ※ The scope and timing of disclosure may vary depending on the severity of the vulnerability, product impact, and remediation status.

  • Q. What qualifies as a reportable item?

    We accept reports regarding the following technical security vulnerabilities:

     

    [In-Scope]

    • Cross-Site Scripting (XSS)
    • Injection vulnerabilities (e.g., SQL Injection)
    • Authentication/Authorization bypass
    • Exposure of sensitive information (e.g., personal data, authentication credentials)
    • Security vulnerabilities caused by server or product misconfiguration
    • Remote Code Execution (RCE)
    • Command Injection
    • Improper file access (e.g., Path Traversal)
    • Weak encryption or authentication methods
    • Exposure of critical authentication credentials (e.g., hardcoded accounts, passwords, or encryption keys)
    • Insecure updates or vulnerabilities in the update verification process
    • Denial of Service (DoS) vulnerabilities resulting from flawed product handling
    • Other security vulnerabilities affecting the confidentiality, integrity, or availability of the product


    [Out-of-Scope]

    • Spam or phishing email reports
    • Social engineering attempts
    • General physical intrusion or access attempts
    • General Denial of Service (DoS/DDoS) attacks themselves
    • Simple security events unrelated to product vulnerabilities
    • Simple re-reports of publicly known vulnerabilities without new information or impact on the product

    If you are unsure whether an issue falls within the scope, please submit a report anyway, we will review it and provide guidance.

  • Q. I’ve discovered a vulnerability; how do I report it?

    We highly value reports from individuals who discover security vulnerabilities and accept vulnerability reports through the following channels.

     

    1.  Website Submission: Please complete the reporting form on the Vulnerability Reporting Page.

    2.  Email Submission: Please send your report to hde.cybersecurity@hd.com

     

    • PGP Encryption: If your report contains sensitive information, we recommend encrypting it using our PGP public key before sending it by email. (PGP Key and Usage Guide)

    • Recommended Information to Include: Detailed description of the vulnerability, reproduction steps, impact scope, and the environment in which it was discovered (browser, operating system, etc.).

    • Response Process: Reports are handled in the following order: Acknowledgment of Receipt → Internal Review → Remediation → Feedback to Reporter. An initial response will be provided within 7 business days of report submission.

    • Personal Data Handling: Personal information provided in a vulnerability report will be retained for two years after the purpose of processing has been fulfilled and will then be securely deleted.