Our cybersecurity commitment

TE Connectivity ("TE") is committed to the security, reliability and resilience of our products and digital solutions. Responsible vulnerability reporting helps protect the connections that support a safer, sustainable, productive and connected future.

 

We welcome good-faith reports from customers, partners, employees and security researchers so potential vulnerabilities can be assessed and addressed appropriately.

 

Security is a shared responsibility. TE applies security principles throughout the product lifecycle and works with customers, partners and security researchers to identify, assess and address potential vulnerabilities. We communicate validated findings and remediation actions when required and comply with applicable cybersecurity requirements.

What to report

Use the link above or email product.security@te.com for a potential vulnerability involving:

 

  • An actively supported TE product, firmware, software or digital service.
  • A TE public-facing website, application or service within the stated scope set out below.
  • Evidence of active exploitation or a security issue that could affect secure or reliable operation. 

 

For general product support, quality concerns, use the relevant TE support channel rather than the vulnerability reporting link.

Responsible Vulnerability Disclosure Policy

Purpose and scope

TE values responsible vulnerability reporting. This policy applies to cybersecurity vulnerabilities affecting TE networkable products, such as those using Bluetooth, Modbus, Wi-Fi, or web interfaces. Unsupported products, third-party services and non-security support matters are out of scope unless TE states otherwise.

How to report

Click the vulnerability reporting link to open an email addressed to the Product Security Incident Response Team (PSIRT) with a pre-populated subject line and body text. Include a description of the vulnerability and potential impact, the affected product, service or URL and version, steps or proof of concept to reproduce the issue, and any relevant screenshots, logs or code. If you wish to be acknowledged or updated, provide your name. Without contact details, TE cannot request clarification or provide status updates.

Good-faith research expectations

  • Act responsibly.
  • Conduct research only within the stated scope.
  • Report immediately if you encounter personal, customer or proprietary information that you are not authorized to access.
  • Do not disrupt services, damage or modify data, conduct denial-of-service attacks or mass automation that could degrade services, spam, use social engineering or phishing, physically tamper with systems, or exfiltrate information.
  • Do not demand payment or use threats, including withholding or publishing information. Do not publicly disclose the issue before coordinating with TE.

What TE will do

  • The Product Security Incident Response Team (PSIRT) mailbox will receive the report. If you provide contact details, PSIRT will send an initial response within three business days.
  • PSIRT will triage the report, assess its impact, request additional information when needed, and prioritize validated vulnerabilities as quickly as possible, with a focus on safety and continuity.
  • Provide progress updates when contact information is available, especially when a fix or mitigation is planned or deployed; notify the reporter when the vulnerability is resolved; and coordinate advisories or CVE issuance where appropriate.

Coordinated disclosure and safe harbor

Please allow TE a reasonable opportunity to investigate and address the issue before public disclosure. TE will work with reporters to coordinate disclosure timing based on risk, affected users and remediation. If you believe the situation warrants immediate public attention, discuss it with TE first. If you act in good faith, follow this policy and avoid harming TE or our users, TE considers your actions legitimate and will not pursue legal action. This safe-harbor commitment is intended to protect responsible security research.

Recognition and compensation

TE does not offer monetary bug bounties for vulnerability reports. With the reporter’s permission, TE may publicly acknowledge a validated contribution after the issue is resolved, for example in a published security advisory.

Questions about the process

If you have questions about this policy or require clarification, contact product.security@te.com. To report a vulnerability, click the reporting link so your email opens with the required recipient, subject line and body text pre-populated.

Frequently Asked Questions

What should I report?

Potential security vulnerabilities affecting in-scope TE products, firmware, software, digital services or public-facing systems.

What is out of scope?

General product support, quality concerns, privacy requests, spam or phishing reports, and issues in unsupported or third-party products unless TE states otherwise.

Can I submit without contact details?

You may choose not to include contact details besides your email address, but TE cannot request clarification or provide updates without them.

What happens after I report?

After you report a potential security vulnerability, the TE Product Security Incident Response Team (PSIRT) reviews the report, may request more information and coordinates next steps.

How quickly will TE respond?

If you provide contact details, the PSIRT will send an initial response within three business days. Resolution time depends on complexity, risk and the affected product or system.

When may I disclose the issue publicly?

Please coordinate with TE and allow reasonable time to investigate and address the issue before public disclosure.

Does TE offer a bug bounty?

TE does not currently operate a monetary bug bounty program. With permission of the respective reporter, TE may acknowledge validated contributions in a published advisory.