Security Bulletins
RayNeo Health publishes security advisories and notices for smart glasses and IoT devices (software, hardware, firmware), detailing newly discovered vulnerabilities, their risk impacts, and remediation plans.
Security Advisory Scope
Disclosure decisions are based on a risk-based evaluation and documented for traceability.
We Publish When
- Vulnerabilities affect supported apps, firmware, or open-source components
- Vulnerabilities have significant security impact (high or critical severity)
- User action or awareness is required
- Vulnerabilities are already publicly known or actively exploited
We May Withhold When
- Disclosure could introduce unacceptable risk with no available mitigation
- The vulnerability affects end-of-life products with no remediation path
- The vulnerability does not apply to real-world deployments
- Legal, regulatory, or contractual restrictions apply
Advisory Content
Each published security advisory may include the following information, presented in a clear and structured format.
- Vulnerability description and technical summary
- Affected products, components, and versions
- Severity rating and impact assessment (confidentiality, integrity, availability)
- Vulnerability identifiers — CVE numbers, advisory IDs, or internal tracking references
- Exploitation conditions required to trigger the vulnerability
- Available mitigations, workarounds, or security updates
- Recommended actions for users
- Publication date and latest revision date
Machine-readable format: Advisories are also published in CSAF v2.0 JSON (ISO/IEC 20153 aligned) for automated vulnerability management. Files are validated for JSON syntax, schema consistency, and required field completeness prior to publication. Available at https://src.rayneo.com/advisories/<advisory-id>.json.
Published Security Advisories
A list of resolved vulnerabilities with publicly available security advisories.
| Advisory ID | Title | Severity | Affected Products | Date | Status | CSAF |
|---|---|---|---|---|---|---|
| No security advisories have been published yet. | ||||||
安全公告
雷鸟创新针对智能眼镜和 IoT 设备(软件、硬件、固件)发布安全公告与通知,详细说明新发现的漏洞、其风险影响及修复计划。
安全公告范围
披露决策基于风险评估,并进行记录以便追溯。
以下情况我们会发布
- 漏洞影响受支持的应用程序、固件或开源组件
- 漏洞具有重大安全影响(高危或严重级别)
- 需要用户采取行动或知晓
- 漏洞已公开或正被积极利用
以下情况我们可能暂缓发布
- 披露可能带来不可接受的风险,且暂无可用缓解措施
- 漏洞影响已停止维护(EOL)且无修复途径的产品
- 漏洞不适用于实际部署环境
- 存在法律、监管或合同限制
公告内容
每份已发布的安全公告可能包含以下信息,并以清晰、结构化的格式呈现。
- 漏洞描述与技术摘要
- 受影响的产品、组件及版本
- 严重性评级与影响评估(机密性、完整性、可用性)
- 漏洞标识符——CVE 编号、公告 ID 或内部跟踪编号
- 触发漏洞所需的利用条件
- 可用的缓解措施、临时解决方案或安全更新
- 对用户的建议操作
- 发布日期与最近修订日期
机器可读格式:公告同时以 CSAF v2.0 JSON(符合 ISO/IEC 20153)发布,用于自动化漏洞管理。文件在发布前会校验 JSON 语法、Schema 一致性及必填字段完整性。地址:https://src.rayneo.com/advisories/<advisory-id>.json。
已发布的安全公告
已解决且已公开发布安全公告的漏洞列表。
| 公告 ID | 标题 | 严重性 | 受影响产品 | 日期 | 状态 | CSAF |
|---|---|---|---|---|---|---|
| 暂无已发布的安全公告。 | ||||||
Security Updates
RayNeo Health provides security updates for our smart glasses and IoT devices (software, hardware, firmware), which can protect you from ever-changing security risks.
Product Support Policy Overview
RayNeo Health is committed to providing continuous security updates for our smart glasses, covering the RayNeo brand.
Updates generally include the latest security patches, vulnerability fixes, and other security improvements. Typically, RayNeo Health will provide security updates for at least 2 years after the first shipment of a certain device model. RayNeo Health regularly publishes and updates the end-of-life (EOL) product list below to help you check whether your smart glasses can receive security updates.
Extended Support: RayNeo Health may support the security updates for 3 years or longer for some models, which are subject to actual conditions. If a very serious security vulnerability is discovered, RayNeo Health may also provide the necessary security fixes to you, even if your device is in the EOL product list.
Product List
| Product Name | Frequency | Release Date | EOL | Declarations |
|---|---|---|---|---|
| RayNeo X3 Pro | 90 Days | 2024-01 | 2027-01 | PSTI |
| RayNeo V4 | 90 Days | 2024-06 | 2027-06 | PSTI |
| RayNeo GT Max | 90 Days | 2024-09 | 2027-09 | PSTI |
| RayNeo GT | 90 Days | 2025-03 | 2028-03 | PSTI |
| RayNeo Air 4 (Pro) | 90 Days | 2025-06 | 2028-06 | PSTI |
EOL Product List
RayNeo Health no longer maintains software or firmware updates (including security updates) for the products listed below. Security vulnerability reports for these products may no longer be accepted.
安全更新
雷鸟创新为我们的智能眼镜和 IoT 设备(软件、硬件、固件)提供安全更新,以保护您免受不断变化的安全风险。
产品支持政策概览
雷鸟创新致力于为我们的智能眼镜提供持续的安全更新,覆盖 RayNeo 品牌。
更新通常包括最新的安全补丁、漏洞修复及其他安全改进。通常情况下,雷鸟创新将在某款设备型号首次出货后至少 2 年 内提供安全更新。雷鸟创新会定期发布并更新下方的产品生命周期终止(EOL)列表,以帮助您确认您的智能眼镜是否仍可接收安全更新。
延长支持:雷鸟创新可能为部分型号提供 3 年或更长时间 的安全更新,具体情况以实际为准。如果发现非常严重的安全漏洞,即使您的设备已在 EOL 列表中,雷鸟创新也可能向您提供必要的安全修复。
产品列表
| 产品名称 | 更新频率 | 发布日期 | EOL | 声明 |
|---|---|---|---|---|
| RayNeo X3 Pro | 90 天 | 2024-01 | 2027-01 | PSTI |
| RayNeo V4 | 90 天 | 2024-06 | 2027-06 | PSTI |
| RayNeo GT Max | 90 天 | 2024-09 | 2027-09 | PSTI |
| RayNeo GT | 90 天 | 2025-03 | 2028-03 | PSTI |
| RayNeo Air 4 (Pro) | 90 天 | 2025-06 | 2028-06 | PSTI |
EOL 产品列表
雷鸟创新不再为下列产品提供软件或固件更新(包括安全更新)。这些产品的安全漏洞报告可能不再被受理。
Incident Response
RayNeo Health attaches great importance to security issues and welcomes all security researchers to report potential security vulnerabilities, helping us improve the security of our smart glasses and IoT devices (software, hardware, firmware).
Vulnerability Response and Disclosure Process
Our structured approach to handling reported vulnerabilities ensures timely and effective resolution.
Recipient
Monitor and assign received vulnerabilities in a timely manner
Verification
Verify the vulnerability and confirm the exploitability and impact
Solution
Development — provide effective fix solutions or risk remediation measures
Affected Scope
Confirmation — investigate and confirm the complete scope of affected products
Publish Advisory
Review and publish the security advisory for the security vulnerability
Reporting a Vulnerability
Mailbox
Submit your findings. Report discovered security vulnerabilities to our dedicated security team.
Your report should contain at least:
- Your organization and contact information
- Products and versions affected
- Description of the potential vulnerability
- Information about known exploits
- Disclosure plans
- Additional information
- Modification or destruction of data
- Service disruption or degradation (e.g. DoS)
- Disclosure of personal, proprietary or financial information
Response Time
48-hour response
RayNeo Health will respond within 48 hours to the vulnerabilities you submit.
Escalation and Decision Making
Escalation criteria are defined based on incident severity and impact to ensure critical vulnerabilities receive appropriate management attention without undue delay.
Escalation Criteria
Escalation may be initiated when any of the following conditions are met:
- Confirmed active exploitation
- Significant impact to users or services
- Widespread product exposure
- Regulatory reporting obligations
- Inability to remediate within defined SLA timelines
Decision Authority
Critical decisions — including public communication and regulatory reporting — are made by authorized roles based on predefined thresholds. Acknowledgement and communication activities may be prioritized or accelerated for vulnerabilities assessed as critical, actively exploited, or associated with significant customer or operational impact.
Timeliness
Escalation may be initiated where acknowledgement timelines are exceeded or communication activities are delayed for critical vulnerability reports. Escalation paths ensure that critical vulnerabilities and significant cybersecurity incidents are brought to the attention of appropriate management levels without undue delay.
Documentation
Escalation records, decisions, and approvals are documented within the vulnerability management process. Escalation procedures support management awareness and corrective actions where communication timelines, acknowledgement expectations, or disclosure coordination activities are delayed or not achieved as expected.
事件响应
雷鸟创新高度重视安全问题,欢迎所有安全研究人员报告潜在的安全漏洞,帮助我们提升智能眼镜和 IoT 设备(软件、硬件、固件)的安全性。
漏洞响应与披露流程
我们处理所报告漏洞的结构化方法可确保及时、有效地解决问题。
接收
及时监控并分配接收到的漏洞
验证
验证漏洞并确认其可利用性与影响
解决
开发有效的修复方案或风险缓解措施
影响范围
调查并确认受影响产品的完整范围
发布公告
审核并发布该安全漏洞的安全公告
报告漏洞
邮箱
提交您的发现。向我们的专业安全团队报告已发现的安全漏洞。
您的报告至少应包含:
- 您所在的组织及联系方式
- 受影响的产品及版本
- 潜在漏洞的描述
- 已知利用方式的信息
- 披露计划
- 其他信息
- 修改或破坏数据
- 服务中断或降级(如 DoS)
- 泄露个人、专有或财务信息
响应时间
48 小时内响应
雷鸟创新将在 48 小时内对您提交的漏洞作出响应。
升级与决策
升级标准根据事件严重程度与影响来定义,以确保严重漏洞得到适当的管理层关注,避免不当延误。
升级标准
满足以下任一条件时,可启动升级:
- 确认存在积极利用
- 对用户或服务产生重大影响
- 产品大范围暴露
- 存在监管报告义务
- 无法在规定的 SLA 时限内完成修复
决策权限
包括公开沟通与监管报告在内的关键决策,由授权角色依据预设阈值作出。对于被评估为严重、被积极利用或与重大客户或运营影响相关的漏洞,其确认与沟通活动可被优先处理或加速。
及时性
当严重漏洞报告的确认时限被超出或沟通活动被延误时,可启动升级。升级路径可确保严重漏洞与重大网络安全事件及时上报至适当的管理层,避免不当延误。
文档记录
升级记录、决策与审批均在漏洞管理流程中进行记录。升级程序支持在沟通时限、确认预期或披露协调活动被延误或未按预期达成时,实现管理层知情与纠正措施。
Security Vulnerabilities
Help us make RayNeo Health products more secure. Report security vulnerabilities and earn rewards through our Security Response Center (SRC) program.
Business Scope Eligible for Security Vulnerabilities
Coverage — In-Scope Domains & Products
- *.rayneo.com
- *.rayneo.cn
- RayNeo App
- RayNeo AR App
- RayNeo XR App
- RayNeo AI App
- WeChat Mini Program
Vulnerability Handling Process
Confirmation & Assessment
The SRC team confirms the vulnerability and begins assessment within one business day.
Resolution & Communication
Within three working days, SRC handles the vulnerability and calculates the contribution value.
Fix & Update
The business department fixes the vulnerability and arranges updates. Timeline depends on severity.
Reviewer's Role
Reporters can review whether fixes are successful and report if the vulnerability can still be exploited.
Internal Triage & Fix SLA
Internal Handling Timeline by Severity
- Critical Triage within 1 business day; fix begins immediately after confirmation
- High Risk Triage and fix within 3–5 working days
- Medium Risk Fix within 15 working days
- Low Risk Fix or address within 30 working days
Ongoing Communication
Status Updates & Verification Outcomes
We maintain ongoing communication with vulnerability reporters and stakeholders throughout the handling lifecycle. Progress updates may be provided at key milestones:
- Initial triage completion
- Validation or reproduction activities
- Remediation planning and availability
- Coordinated disclosure preparation
- Case closure
Additional updates may be triggered by significant changes in vulnerability severity, exploitation status, remediation timelines, or other material developments. For critical or actively exploited vulnerabilities, communication may be accelerated to support timely coordination and risk reduction.
Verification outcomes: Reporters will be informed of verification results — confirmation of a valid vulnerability, inability to reproduce the issue, requests for additional information, duplicate report determination, or out-of-scope classification. All communications are recorded within the vulnerability tracking process.
Continuity: Communication is maintained throughout the lifecycle, including during escalation situations, personnel transitions, or operational continuity events.
Vulnerability Communication Roles & Responsibilities
Clear division of responsibilities across departments ensures a structured and accountable vulnerability response process.
| Role | Responsibilities |
|---|---|
| Security Department | Vulnerability confirmation, investigation, classification, tracking, and closure; coordinate remediation across teams; maintain analysis documentation and archival; manage reward and penalty for vulnerability handling. |
| Business Department | Remediate vulnerabilities within departmental scope; promptly report discovered vulnerabilities to Security Department; cooperate on fixes and root cause analysis; assist with investigation and evidence collection. |
| Legal Department | Provide legal support during security incidents; assist with evidence collection and legal proceedings in case of disputes. |
Vulnerability Rating Rules
RayNeo Health evaluates reported vulnerabilities using the Common Vulnerability Scoring System, CVSS v4.0, where applicable. Each report is assigned a CVSS Base Score, which determines the severity rating and corresponding reward level.
The assessment considers factors including:
- Exploitability
- Attack complexity and required privileges
- User interaction requirements
- Exposure of the affected asset
- Impact on confidentiality, integrity, and availability
- Potential customer, operational, privacy, or safety impact
- Active exploitation or availability of public exploit code
- Availability of compensating controls or mitigations
RayNeo Health may adjust remediation priority based on product context, affected deployment environments, exploitation status, customer impact, and other relevant business or regulatory risks.
| Severity | CVSS v4.0 Score | Description | Target Remediation Time |
|---|---|---|---|
| Critical | 9.0 – 10.0 | Vulnerabilities that may result in severe security impact, such as remote code execution, major unauthorized system access, significant data exposure, widespread compromise, or active exploitation. | Within 30 days |
| High Risk | 7.0 – 8.9 | Vulnerabilities that may allow significant unauthorized access, privilege escalation, sensitive information exposure, or substantial compromise under realistic attack conditions. | Within 60 days |
| Medium Risk | 4.0 – 6.9 | Vulnerabilities requiring user interaction or specific conditions to obtain user data, partial information disclosure, stored cross-site scripting, or non-critical authentication flaws. | Within 90 days |
| Low Risk | 0.1 – 3.9 | Vulnerabilities with limited impact, such as minor information disclosure in non-mainstream environments, local denial-of-service, blind SSRF without response data, or URL redirect under defined subdomains. | Within 180 days |
| Invalid | 0.0 | Reports with no immediate security issue, unable to be directly exploited, or unable to be reproduced. Examples include unrelated bugs, scanner-only reports, self-XSS, undocumented guesswork, or non-RayNeo Health business. | Not applicable |
Security Testing Considerations
- The reward standard is only for threat intelligence affecting RayNeo Health products and business.
- The right to interpret the processing procedures and grading rules belongs to RayNeo Health.
- Researchers are not allowed to disclose vulnerability details on any public channels.
- Multiple vulnerabilities from the same source are counted as one; only the earliest submitter is credited.
- The final contribution value is determined by factors including difficulty and scope of influence.
- It is strictly forbidden to use automated scans or auxiliary tools for high-frequency scanning.
- It is strictly forbidden to use vulnerabilities for illegal operations (e.g. data theft, lateral movement).
- Do not use security testing to damage user interests, affect normal operations, or steal user data.
Secure Disclosure — Report a Vulnerability
Submit your findings through the secure form below. Fields marked with an asterisk (*) are required.
安全漏洞
帮助我们让雷鸟创新产品更加安全。通过我们的安全响应中心(SRC)计划报告安全漏洞并赢取奖励。
可获安全漏洞的业务范围
覆盖范围 — 范围内的域名与产品
- *.rayneo.com
- *.rayneo.cn
- RayNeo App
- RayNeo AR App
- RayNeo XR App
- RayNeo AI App
- 微信小程序
漏洞处理流程
确认与评估
SRC 团队在一个工作日内确认漏洞并开始评估。
解决与沟通
三个工作日内,SRC 处理漏洞并计算贡献值。
修复与更新
业务部门修复漏洞并安排更新,时限视严重程度而定。
报告者角色
报告者可复核修复是否成功,若漏洞仍可被利用则可再次报告。
内部分诊与修复 SLA
按严重程度划分的内部处理时限
- 严重 1 个工作日内分诊;确认后立即开始修复
- 高危 3–5 个工作日内分诊并修复
- 中危 15 个工作日内修复
- 低危 30 个工作日内修复或处理
持续沟通
状态更新与验证结果
我们在整个处理生命周期内与漏洞报告者及利益相关方保持持续沟通。关键节点可能提供进度更新:
- 初始分诊完成
- 验证或复现活动
- 修复计划与可用性
- 协调披露准备
- 结案
漏洞严重性、利用状态、修复时限或其他重大进展发生显著变化时,可能触发额外更新。对于严重或被积极利用的漏洞,可加速沟通以支持及时协调与降低风险。
验证结果:报告者将被告知验证结果——确认为有效漏洞、无法复现问题、要求补充信息、判定为重复报告或分类为范围之外。所有沟通均记录在漏洞跟踪流程中。
连续性:在整个生命周期内保持沟通,包括升级情形、人员变动或运营连续性事件期间。
漏洞沟通角色与职责
跨部门清晰的职责划分可确保结构化、可问责的漏洞响应流程。
| 角色 | 职责 |
|---|---|
| 安全部门 | 漏洞确认、调查、分级、跟踪与结案;跨团队协调修复;维护分析文档与归档;管理漏洞处理相关的奖惩。 |
| 业务部门 | 在部门范围内修复漏洞;及时向安全部门报告发现的漏洞;配合修复与根因分析;协助调查与证据收集。 |
| 法务部门 | 在安全事件期间提供法律支持;发生争议时协助证据收集与法律程序。 |
漏洞评级规则
雷鸟创新在适用情况下采用通用漏洞评分系统 CVSS v4.0 评估所报告的漏洞。每份报告均被赋予 CVSS 基础分,用于确定严重性评级及相应的奖励等级。
评估考虑的因素包括:
- 可利用性
- 攻击复杂度与所需权限
- 用户交互要求
- 受影响资产的暴露程度
- 对机密性、完整性、可用性的影响
- 潜在的客户、运营、隐私或安全影响
- 积极利用或公开利用代码的可用性
- 补偿性控制或缓解措施的可用性
雷鸟创新可能根据产品背景、受影响部署环境、利用状态、客户影响及其他相关业务或监管风险来调整修复优先级。
| 严重性 | CVSS v4.0 评分 | 说明 | 目标修复时间 |
|---|---|---|---|
| 严重 | 9.0 – 10.0 | 可能导致严重安全影响的漏洞,例如远程代码执行、大规模未授权系统访问、重大数据泄露、广泛失陷或正被积极利用。 | 30 天内 |
| 高危 | 7.0 – 8.9 | 在现实攻击条件下可能造成显著未授权访问、权限提升、敏感信息泄露或重大失陷的漏洞。 | 60 天内 |
| 中危 | 4.0 – 6.9 | 需用户交互或特定条件方可获取用户数据、部分信息泄露、存储型跨站脚本或非关键认证缺陷的漏洞。 | 90 天内 |
| 低危 | 0.1 – 3.9 | 影响有限的漏洞,例如非主流环境下的轻微信息泄露、本地拒绝服务、无响应数据的盲 SSRF,或指定子域下的 URL 跳转。 | 180 天内 |
| 无效 | 0.0 | 无直接安全问题、无法直接利用或无法复现的报告。例如无关缺陷、纯扫描器报告、self-XSS、无依据的猜测或非雷鸟创新业务。 | 不适用 |
安全测试注意事项
- 奖励标准仅适用于影响雷鸟创新产品与业务的威胁情报。
- 处理流程与分级规则的最终解释权归雷鸟创新所有。
- 研究人员不得在任何公开渠道披露漏洞细节。
- 来自同一来源的多个漏洞按一个计算;仅记最早的提交者。
- 最终贡献值由难度与影响范围等因素综合确定。
- 严禁使用自动化扫描或辅助工具进行高频扫描。
- 严禁利用漏洞进行非法操作(如窃取数据、横向移动)。
- 不得利用安全测试损害用户利益、影响正常运营或窃取用户数据。
安全披露 — 报告漏洞
通过下方安全表单提交您的发现。带星号(*)的字段为必填项。