top of page


SPY VIDEO CAR POLICY
1. Vulnerability Disclosure Policy:
-
Policy Description: We have established a public security vulnerability disclosure and feedback mechanism for our remote control toy car products equipped with Wi-Fi cameras. We welcome external researchers to submit security vulnerabilities and risks related to device security, network transmission, camera/video capture, data privacy, Wi-Fi connectivity, and the companion control software. We will centrally receive, evaluate, and fix these issues, providing timely feedback to continuously ensure device safety, user privacy, and network compliance.
-
Scope:
1. Product Scope: Remote control toy car series equipped with Wi-Fi cameras.
2. Hardware Scope: RC car mainboard, Wi-Fi module, camera module, and power supply hardware.
3. Software Scope: Device built-in firmware, Wi-Fi data transmission programs, companion control APP, and real-time video transmission programs.
4. Exclusions: Third-party non-original modified devices and non-official companion software are not included.
-
Contact:
1. Email: info@spyxhq.com
2. Phone: (852) 3105 2282 3. Address: Room 222, 1/F, Fonda Industrial Building, 37-39 Au Pui Wan Street, FoTan, N.T. Hong Kong
-
Required Submission Details:
1. Description of the vulnerability and explanation of its risk/impact.
2. Specific product model, firmware version, and APP version.
3. Steps to reproduce the vulnerability and the testing environment.
4. Supporting materials such as screenshots and screen recordings.
5. Submitter's contact information for progress updates.
-
Timeline:
1. We will acknowledge receipt of the vulnerability report within 7 business days.
2. We will complete vulnerability verification and risk assessment, and provide a formal response within 9 business days.
3. Within 9 business days after the vulnerability is fixed, we will complete the version update and release the solution.
4. We will proactively notify the reporter of key processing milestones within 5 business days.
5. All firmware and APP version upgrades will strictly maintain version consistency for the same product model.
-
Submission Rules:
1. Submissions are strictly for good-faith security research and vulnerability reporting. Using vulnerabilities for illegal intrusion, stealing camera footage, leaking user privacy, malicious attacks, or illicit profit is prohibited.
2. Submitting false, duplicate, or harmless/invalid vulnerability reports is prohibited.
3. Before the vulnerability is fixed, the submitter must not publicly disclose or disseminate details of the vulnerability.
4. Destructive testing and large-scale illegal intrusion testing on this product are strictly prohibited.
5. We commit to handling compliant, good-faith vulnerability submissions in a friendly and cooperative manner.
2. Product Support Information:
-
Product Name: Spy Video Car
-
Product Model: #10556
-
Software/Firmware Release Date: January 1, 2025
-
Firmware Version: Wi-Fi Version: B8.2220.HOTO7.KADINGCAR
-
Security Update Support End Date: January 10, 2028
bottom of page