Security Bounty

Help us make Zepp Health products more secure. Report security vulnerabilities and earn rewards through our Security Response Center (SRC) program.

Business Scope Eligible for Security Rewards

Coverage

In-Scope Domains & Products

  • *.huami.com
  • *.amazfit.com
  • *.zepp.com
  • *.zepphealth.com
  • Zepp App
  • Zepp Life App
  • WeChat Mini Program
Note: Some independently operated regional websites are not within the scope of the reward (e.g. tr.amazfit.com, co.amazfit.com, in.amazfit.com, tw.amazfit.com).

Vulnerability Handling Process

Confirmation & Assessment

The SRC team confirms the vulnerability and begins assessment within one business day.

Resolution & Communication

Within three working days, SRC handles the vulnerability and calculates the contribution value.

Fix & Update

The business department fixes the vulnerability and arranges updates. Timeline depends on severity.

Reviewer's Role

Reporters can review whether fixes are successful and report if the vulnerability can still be exploited.

Internal Triage & Fix SLA

Internal Handling Timeline by Severity

  • Critical — Triage within 1 business day; fix begins immediately after confirmation
  • High Risk — Triage and fix within 3–5 working days
  • Medium Risk — Fix within 15 working days
  • Low Risk — Fix or address within 30 working days
Note: The timelines above are Zepp Health's internal handling SLA from report to internal fix completion. The Target Remediation Time shown in the Rating Rules table below is the customer-facing patch release window, which includes validation, regression testing, staged rollout, and coordinated disclosure preparation.
Ongoing Communication

Status Updates & Verification Outcomes

We maintain ongoing communication with vulnerability reporters and stakeholders throughout the handling lifecycle. Progress updates may be provided at key milestones:

  • Initial triage completion
  • Validation or reproduction activities
  • Remediation planning and availability
  • Coordinated disclosure preparation
  • Case closure

Additional updates may be triggered by significant changes in vulnerability severity, exploitation status, remediation timelines, or other material developments. For critical or actively exploited vulnerabilities, communication may be accelerated to support timely coordination and risk reduction.

Verification outcomes: Reporters will be informed of verification results — confirmation of a valid vulnerability, inability to reproduce the issue, requests for additional information, duplicate report determination, or out-of-scope classification. All communications are recorded within the vulnerability tracking process.
Continuity: Communication is maintained throughout the lifecycle, including during escalation situations, personnel transitions, or operational continuity events.

Vulnerability Communication Roles & Responsibilities

Clear division of responsibilities across departments ensures a structured and accountable vulnerability response process.

RoleResponsibilities
Security Department Vulnerability confirmation, investigation, classification, tracking, and closure; coordinate remediation across teams; maintain analysis documentation and archival; manage reward and penalty for vulnerability handling.
Business Department Remediate vulnerabilities within departmental scope; promptly report discovered vulnerabilities to Security Department; cooperate on fixes and root cause analysis; assist with investigation and evidence collection.
Legal Department Provide legal support during security incidents; assist with evidence collection and legal proceedings in case of disputes.

Vulnerability Rating Rules

Zepp Health evaluates reported vulnerabilities using the Common Vulnerability Scoring System, CVSS v4.0, where applicable. Each report is assigned a CVSS Base Score, which determines the severity rating and corresponding reward level.

The assessment considers factors including:

  • Exploitability;
  • Attack complexity and required privileges;
  • User interaction requirements;
  • Exposure of the affected asset;
  • Impact on confidentiality, integrity, and availability;
  • Potential customer, operational, privacy, or safety impact;
  • Active exploitation or availability of public exploit code;
  • Availability of compensating controls or mitigations.

Zepp Health may adjust remediation priority based on product context, affected deployment environments, exploitation status, customer impact, and other relevant business or regulatory risks.

Vulnerability severity levels with CVSS v4.0 score range, description and target remediation time
Severity CVSS v4.0 Score Description Target Remediation Time
Critical 9.0 – 10.0 Vulnerabilities that may result in severe security impact, such as remote code execution, major unauthorized system access, significant data exposure, widespread compromise, or active exploitation. Within 30 days
High Risk 7.0 – 8.9 Vulnerabilities that may allow significant unauthorized access, privilege escalation, sensitive information exposure, or substantial compromise under realistic attack conditions. Within 60 days
Medium Risk 4.0 – 6.9 Vulnerabilities requiring user interaction or specific conditions to obtain user data, partial information disclosure, stored cross-site scripting, or non-critical authentication flaws. Within 90 days
Low Risk 0.1 – 3.9 Vulnerabilities with limited impact, such as minor information disclosure in non-mainstream environments, local denial-of-service, blind SSRF without response data, or URL redirect under defined subdomains. Within 180 days
Invalid 0.0 Reports with no immediate security issue, unable to be directly exploited, or unable to be reproduced. Examples include unrelated bugs, scanner-only reports, self-XSS, undocumented guesswork, or non-Zepp Health business. Not applicable
Scoring note: The CVSS v4.0 Base Score determines the severity rating; final severity may be adjusted based on environmental factors and actual impact. The examples in the rating table are illustrative — for vulnerabilities not explicitly described, severity is determined by the CVSS Base Score. Refer to the CVSS v4.0 specification for full scoring details.

SRC Rewards Program

$300
Max Critical
$150
Max High Risk
$100
Max Medium
48h
Response Time
Security vulnerability reward amounts by severity level
LevelBug Bounty (USD)Remark
Critical$150 - $300Zepp Health product portfolio, based on vulnerability value assessment
High Risk$100 - $150A single Zepp Health product
Medium Risk$20 - $100A single Zepp Health product
Low RiskWritten Thanks/
InvalidNone/
Distribution

Reward Distribution Mechanism

After reviewing the vulnerability, the security team assigns the corresponding reward according to the rating standard. The reward takes effect after confirming with the researcher. After confirming the relevant rewards and personal information, the security team arranges for distribution. The actual payment processing time may vary by region.

Security Testing Considerations

  • The reward standard is only for threat intelligence affecting Zepp Health products and business.
  • The right to interpret the processing procedures and grading rules belongs to Zepp Health.
  • Researchers are not allowed to disclose vulnerability details on any public channels.
  • Multiple vulnerabilities from the same source are counted as one; only the earliest submitter is credited.
  • The final contribution value is determined by factors including difficulty and scope of influence.
  • It is strictly forbidden to use automated scans or auxiliary tools for high-frequency scanning.
  • It is strictly forbidden to use vulnerabilities for illegal operations (e.g. data theft, lateral movement).
  • Do not use security testing to damage user interests, affect normal operations, or steal user data.

Questions? Contact us:

Secure Disclosure

Submit a Vulnerability Report

Complete and submit the secure form below without leaving this page. You can include vulnerability details and supporting attachments for the Zepp Health security team.

Before submitting: Do not include unnecessary personal data. Please provide only the information and attachments needed to reproduce and assess the vulnerability.

If the form is temporarily unavailable, contact sec@zepp.com. Please do not send sensitive attachments by email unless instructed by the security team.