Security Bounty
Help us make Zepp Health products more secure. Report security vulnerabilities and earn rewards through our Security Response Center (SRC) program.
Business Scope Eligible for Security Rewards
In-Scope Domains & Products
- *.huami.com
- *.amazfit.com
- *.zepp.com
- *.zepphealth.com
- Zepp App
- Zepp Life App
- WeChat Mini Program
Vulnerability Handling Process
Confirmation & Assessment
The SRC team confirms the vulnerability and begins assessment within one business day.
Resolution & Communication
Within three working days, SRC handles the vulnerability and calculates the contribution value.
Fix & Update
The business department fixes the vulnerability and arranges updates. Timeline depends on severity.
Reviewer's Role
Reporters can review whether fixes are successful and report if the vulnerability can still be exploited.
Internal Handling Timeline by Severity
- Critical — Triage within 1 business day; fix begins immediately after confirmation
- High Risk — Triage and fix within 3–5 working days
- Medium Risk — Fix within 15 working days
- Low Risk — Fix or address within 30 working days
Status Updates & Verification Outcomes
We maintain ongoing communication with vulnerability reporters and stakeholders throughout the handling lifecycle. Progress updates may be provided at key milestones:
- Initial triage completion
- Validation or reproduction activities
- Remediation planning and availability
- Coordinated disclosure preparation
- Case closure
Additional updates may be triggered by significant changes in vulnerability severity, exploitation status, remediation timelines, or other material developments. For critical or actively exploited vulnerabilities, communication may be accelerated to support timely coordination and risk reduction.
Vulnerability Communication Roles & Responsibilities
Clear division of responsibilities across departments ensures a structured and accountable vulnerability response process.
| Role | Responsibilities |
|---|---|
| Security Department | Vulnerability confirmation, investigation, classification, tracking, and closure; coordinate remediation across teams; maintain analysis documentation and archival; manage reward and penalty for vulnerability handling. |
| Business Department | Remediate vulnerabilities within departmental scope; promptly report discovered vulnerabilities to Security Department; cooperate on fixes and root cause analysis; assist with investigation and evidence collection. |
| Legal Department | Provide legal support during security incidents; assist with evidence collection and legal proceedings in case of disputes. |
Vulnerability Rating Rules
Zepp Health evaluates reported vulnerabilities using the Common Vulnerability Scoring System, CVSS v4.0, where applicable. Each report is assigned a CVSS Base Score, which determines the severity rating and corresponding reward level.
The assessment considers factors including:
- Exploitability;
- Attack complexity and required privileges;
- User interaction requirements;
- Exposure of the affected asset;
- Impact on confidentiality, integrity, and availability;
- Potential customer, operational, privacy, or safety impact;
- Active exploitation or availability of public exploit code;
- Availability of compensating controls or mitigations.
Zepp Health may adjust remediation priority based on product context, affected deployment environments, exploitation status, customer impact, and other relevant business or regulatory risks.
| Severity | CVSS v4.0 Score | Description | Target Remediation Time |
|---|---|---|---|
| Critical | 9.0 – 10.0 | Vulnerabilities that may result in severe security impact, such as remote code execution, major unauthorized system access, significant data exposure, widespread compromise, or active exploitation. | Within 30 days |
| High Risk | 7.0 – 8.9 | Vulnerabilities that may allow significant unauthorized access, privilege escalation, sensitive information exposure, or substantial compromise under realistic attack conditions. | Within 60 days |
| Medium Risk | 4.0 – 6.9 | Vulnerabilities requiring user interaction or specific conditions to obtain user data, partial information disclosure, stored cross-site scripting, or non-critical authentication flaws. | Within 90 days |
| Low Risk | 0.1 – 3.9 | Vulnerabilities with limited impact, such as minor information disclosure in non-mainstream environments, local denial-of-service, blind SSRF without response data, or URL redirect under defined subdomains. | Within 180 days |
| Invalid | 0.0 | Reports with no immediate security issue, unable to be directly exploited, or unable to be reproduced. Examples include unrelated bugs, scanner-only reports, self-XSS, undocumented guesswork, or non-Zepp Health business. | Not applicable |
SRC Rewards Program
| Level | Bug Bounty (USD) | Remark |
|---|---|---|
| Critical | $150 - $300 | Zepp Health product portfolio, based on vulnerability value assessment |
| High Risk | $100 - $150 | A single Zepp Health product |
| Medium Risk | $20 - $100 | A single Zepp Health product |
| Low Risk | Written Thanks | / |
| Invalid | None | / |
Reward Distribution Mechanism
After reviewing the vulnerability, the security team assigns the corresponding reward according to the rating standard. The reward takes effect after confirming with the researcher. After confirming the relevant rewards and personal information, the security team arranges for distribution. The actual payment processing time may vary by region.
Security Testing Considerations
- The reward standard is only for threat intelligence affecting Zepp Health products and business.
- The right to interpret the processing procedures and grading rules belongs to Zepp Health.
- Researchers are not allowed to disclose vulnerability details on any public channels.
- Multiple vulnerabilities from the same source are counted as one; only the earliest submitter is credited.
- The final contribution value is determined by factors including difficulty and scope of influence.
- It is strictly forbidden to use automated scans or auxiliary tools for high-frequency scanning.
- It is strictly forbidden to use vulnerabilities for illegal operations (e.g. data theft, lateral movement).
- Do not use security testing to damage user interests, affect normal operations, or steal user data.
Questions? Contact us: sec@zepp.com
Submit a Vulnerability Report
Complete and submit the secure form below without leaving this page. You can include vulnerability details and supporting attachments for the Zepp Health security team.
If the form is temporarily unavailable, contact sec@zepp.com. Please do not send sensitive attachments by email unless instructed by the security team.