Security Bulletins
Zepp Health publishes security advisories and notices for smartwatches and IoT devices (software, hardware, firmware), detailing newly discovered vulnerabilities, their risk impacts, and remediation plans.
Security Advisory Scope
We publish security advisories based on a risk-based evaluation, and every disclosure decision is documented for traceability.
- A vulnerability affects a published and supported app, embedded system, or open-source component
- A vulnerability has significant security impact (high or critical severity)
- User action or awareness is required
- A vulnerability is already publicly known or actively exploited
- Where a documented evaluation shows that the cybersecurity risk of full publication outweighs the security benefit, detailed disclosure may be delayed and the reason and planned publication conditions are recorded
Advisory Content
Each published advisory includes the following information, where applicable, presented in a clear and structured format.
- Vulnerability description and technical summary
- Affected products, components, and versions
- Severity rating and impact assessment
- Potential security impact on confidentiality, integrity, availability, and safety where relevant
- Vulnerability identifiers — CVE numbers, advisory IDs, or internal tracking references
- Exploitation conditions required to trigger the vulnerability
- Available mitigations, workarounds, and security updates or patches
- Recommended actions for users
- Initial publication and latest revision dates
- Contact information for vulnerability-related enquiries
Advisory Presentation and Readability
Advisories are presented in a clear, structured, and human-readable format so affected users, customers, integrators, and other stakeholders can understand the security impact and act.
- Written in clear, understandable language for the intended audience
- Affected products, versions, and components presented in a structured, easily identifiable manner
- Remediation instructions, mitigation guidance, or update references provided in an actionable format
- Severity or risk information clearly identified
- Consistent formatting — headings, sections, tables, and bullet points — to support readability and navigation
- Essential security information does not depend on machine-readable formats or specialized tools
Machine-readable advisories complement, and do not replace, the human-readable security advisory. Each is generated and maintained in structured JSON (CSAF v2.0) and includes the following standardized sections:
- Document metadata
- Publisher and tracking information
- Product tree and affected product identification
- Vulnerability descriptions and identifiers
- Product status information
- Impact and severity details
- Remediation and mitigation information
- References to related advisories, CVEs, or external resources
https://src.zepp.com/advisories/<advisory-id>.json and validated for JSON syntax, schema consistency, and required field completeness prior to publication.Exception to Vulnerability Publication
Vulnerabilities resolved through remediation are normally published. Publication is omitted only when all of the following conditions are met.
- The vulnerability has been fully remediated
- Deployment of the remediation is fully under the organization's control and requires no action by customers or users
- No residual risk remains for users, and no user awareness, mitigation activity, configuration change, or security action is required
- The vulnerability exists solely within a remote data processing solution, cloud service, or backend infrastructure component, and has been fully remediated before disclosure
Published Security Advisories
A list of resolved vulnerabilities with publicly available security advisories.
| Advisory ID | Title | Severity | Affected Products | Date | Status | CSAF |
|---|---|---|---|---|---|---|
| Loading advisories… | ||||||