UK PSTI Compliance

 

Information On How to Report Security Issues

 

Protecting our customers from threats to their security is always an important task for OUKITEL. As a key player in global Networking and Smart Home markets, we will do our utmost to provide our users with secure stable products and services, and to strictly protect the privacy and security of their data.

We welcome and encourage all reports related to product security or user privacy. We will follow established processes to address them and provide timely feedback.

 

Report Vulnerabilities to OUKITEL

 

We strongly encourage organizations and individuals to contact OUKITEL’s security team to report any potential security issue.

To report a security or privacy vulnerability, please send an email to info@oukitel.com with the product model and software version, describe the detailed security issue to us. OUKITEL will endeavor to respond to the report within 5 working days.

OUKITEL will need to obtain detailed information about the reported vulnerability to more accurately and quickly begin the verification process.

 

Responsible Reporting Guidelines

 

  1. All parties to a vulnerability disclosure should comply with the laws of their country or region.
  2. Vulnerability reports should be based on the latest released firmware, and preferably written in English.
  3. Report vulnerabilities through the dedicated communication channel. OUKITELmay receive reports from other channels but does not guarantee that the report will be acknowledged.
  4. Adhere to data protection principles at all times and do not violate the privacy and data security of OUKITEL’s users, employees, agents, services or systems during the vulnerability discovery process.
  5. Maintain communication and cooperation during the disclosure process and avoid disclosing information about the vulnerability prior to the negotiated disclosure date.
  6. OUKITELis not currently operating a vulnerability bounty program.

 

How OUKITEL Deals with Vulnerabilities

 

            

 

OUKITEL encourages customers, vendors, independent researchers, security organizations, etc. to proactively report any potential vulnerabilities to the security team. At the same time, OUKITEL will proactively obtain information about vulnerabilities in OUKITEL products from the community, vulnerability repositories and various security websites. In order to be aware of vulnerabilities as soon as they are discovered.

OUKITEL will respond to vulnerability reports as soon as possible, usually within 5 business days.

OUKITEL Security will work with the product team to perform a preliminary analysis and validation of the report to determine the validity, severity, and impact of the vulnerability. We may contact you if we need more information about the reported vulnerability.

Once the vulnerability has been identified, we will develop and implement a remediation plan to provide a solution for all affected customers.

Remediation typically takes up to 90 days and in some cases may take longer.

You can keep up to date with our progress and the completion of any remediation activities.

OUKITEL will issue a security advisory when one or more of the following conditions are met:

  1. The severity of the vulnerability is rated CRITICAL by the OUKITELsecurity team and OUKITEL has completed the vulnerability response process and sufficient mitigation solutions are available to assist customers in eliminating all security risks.
  2. If the vulnerability has been actively exploited and is likely to increase the security risk to OUKITELcustomers, or if the vulnerability is likely to increase public concern about the security of OUKITEL products, OUKITEL will expedite the release of a security bulletin about the vulnerability, which may or may not include a full firmware patch or emergency fix.

 

Information on Minimum Security Update Periods

 

The Support Period for OUKITEL components is actively maintained considering security updates from Jan 2024 to Jan 2027.

*This list is constantly being updated and subject to change without notice.

 

Models

Versions

Description

C21 Plus, C31, C31 Pro, C32, C32 Pro, C33, C35, C36, C37, C38, C39, C50, C51, C52, C53, C55, C56, C57, C57S, C57 Pro, C58, C58 Pro, C59, C60, C61, C62, C63, C65, C66, K15 Plus, K16, K17, K18, K19, K20, WP15, WP16, WP17, WP18 Pro, W18, WP19, WP19 Pro, WP20, WP20 Pro, WP21, WP21 Ultra, WP22, WP23, WP23 Pro, WP26, WP27, WP28, WP28S, WP28E, WP28 Pro, WP29, WP30 Pro, WP31, WP32, WP32 Pro, WP33 Pro, WP35, WP35S, WP36, WP36 Pro, WP37, WP38, WP39, WP50, WP51, WP52, WP53, WP55, WP56, WP57, S1, S2, S3, S5, S6, S7, X1, X1 Pro, X2, X3, X5, TITAN, TITAN Pro, TITAN2, TITAN3, TITAN5, P1, P2, P3, P5, P6, G1, G2, G3, G5, G6, G7

V01

Smartphone

OKT3, OT5, OT5 S, OT6, OT6 Kids, OT7 , OT8, OT9, OT10, OT11, OT12, OT13, OT15, OT16, OT17, OT18, OT19, OT20, OT22, OT23, OT25, RT1, RT2, RT3, RT3 Pro, RT3 Plus, RT5, RT6, RT7 TITAN, RT7 TITAN 5G, RT8, RT9, RT10, RT12, RT13, RT15, RT16, RT17, RT18, RT19, RT20, GT1, GT2, GT3, GT5, GT6, GT7, GT8, GT9, GT10

V01

Tablet