We protect the integrity of Cheery Energy products by working with security researchers, customers, and partners to handle vulnerabilities with professionalism and transparency.
The Cheery Energy Product Security Incident Response Team is a dedicated group responsible for receiving, investigating, coordinating, and disclosing security vulnerabilities in our products. We operate under ISO/IEC 29147 and ISO/IEC 30111 standards.
Receive vulnerability reports from researchers, customers, and the public. Classify and validate every submission.
Coordinate with R&D, product management, and quality teams to develop and test mitigations.
Publish security advisories with coordinated disclosure, providing customers with clear mitigation guidance.
Feed vulnerability insights back into the product development lifecycle to raise the security baseline.
We highly value coordinated vulnerability reports from the security community — researchers, academics, customers, and partners alike.
Document the affected product model, firmware version, detailed vulnerability description, reproduction steps, and impact assessment.
Use our PGP public key below to encrypt sensitive vulnerability information before sending.
Email your encrypted report to psirt@cheeryenergy.com.
We commit to acknowledging receipt within 2 business days and will assign a tracking ID to your case.
Download our PGP public key to encrypt sensitive vulnerability reports.
Security advisories for Cheery Energy products, published under our coordinated disclosure policy once mitigations are available.
| Advisory ID | Affected Product | Severity | CVE | Date | |
|---|---|---|---|---|---|
| Loading advisories… | |||||
Cheery Energy follows the Coordinated Vulnerability Disclosure (CVD) model. We ask reporters to:
To help us triage and validate efficiently, please include as much of the following as possible:
Model number, hardware revision, firmware/software version.
Type (CWE reference), affected component or functional module.
Detailed steps, proof-of-concept code (if available), test environment configuration.
Potential security impact, suggested CVSS score if available.
Date of discovery, whether already public, any planned disclosure timeline.
Reporter name/alias, PGP public key, preferred method of contact.
Confirmation within 2 business days. Tracking ID assigned.
PSIRT assesses validity and severity (CVSS scoring).
Product teams develop fixes or mitigations in coordination with PSIRT.
Disclosure date agreed with reporter. Security advisory published.