Vulnerability Disclosure Policy (Coordinated Vulnerability Disclosure Policy)
Last Updated: 24 August 2026
Fujikura Ltd. is committed to improving the cybersecurity of our products and services and welcome reports of security vulnerabilities submitted in good faith. If you believe you have discovered a vulnerability to one of our products or services, please report it in accordance with this policy.
Scope
The following Fujikura products and services are covered by this policy:
- Fusion splicers, fusion splicer-related tools, and ID testers
- PC applications and smartphone applications for fusion splicers and related tools
- Cloud services and related web services provided for fusion splicers and related tools
The following are outside the scope of this policy:
- Third-party software
- Services operated by third parties
- Products designated by our company as End-of-Support products*
* Vulnerability reports for End-of-Support products are still welcome; however, we do not guarantee that remediation, updates, or other corrective measures will be provided.
How to Report a Vulnerability
If you discover a vulnerability, please contact us using the following information:
Email:
security_splicer@jp.fujikura.com
PGP Public Key:
Please download the PGP public key using the "Download PGP Public Key" button below.
Fingerprint:
B06C DFAF 5C0B CE36 F817
7C3F 7936 5F38 3330 8144
We strongly encourage the use of encrypted communication whenever possible.
Information to Include in Your Report
Please provide the following information:
- Product name
- Software version (if known)
- Description of the vulnerability, including its potential impact
- Steps required to reproduce the issue
If possible, please also provide:
- Your name (or preferred alias/handle)
- Contact email address
- Date when the vulnerability was discovered
- Attack prerequisites or conditions
- Expected impact
- Proof-of-Concept (PoC) code or details, if available
- Any other relevant information
Personal Information
Before providing personal information, please review our Privacy Policy.
Any personal information provided will be used for vulnerability handling and other legitimate business purposes. Where required by law, or where necessary for vulnerability management activities, information may be shared with contractors, certification bodies, vulnerability management organizations, regulatory authorities, or other relevant parties.
Attachments
Please use the following file formats when submitting attachments:
pdf, txt, log, png, jpg, jpeg, csv, json, xml, yaml, zip, pcap, pcapng
Please do not include executable files such as:
exe, dll, msi, bat, cmd, ps1
within ZIP archives.
Whenever possible, attachments should be encrypted using PGP/GPG and submitted in formats such as:
.pgp, .gpg, .asc
For encrypted files, please ensure that the original file type can be identified from the filename.
Example: report.pdf → report.pdf.asc
Our Response
We will acknowledge receipt of your report within three (3) business days whenever contact information is provided.
Reported vulnerability information will be recorded, managed, evaluated, and handled in accordance with our vulnerability management process.
Where contact information is available, we will make reasonable efforts to keep you informed of the progress of our investigation. We may also contact you if additional information or clarification is required.
Information provided by us during the investigation process may contain confidential information. If you intend to publicly disclose such information, please consult with us beforehand.
Compliance with the EU Cyber Resilience Act (CRA)
To comply with the EU Cyber Resilience Act (CRA), if we become aware of an actively exploited vulnerability or a severe incident that significantly impacts the security of our products, we may report such information within the legally prescribed timeframes to ENISA and/or other authorities designated under applicable laws and regulations.
Where we determine that disclosure is required by law or regulation, we may share all or part of the vulnerability information with ENISA, CSIRTs, or other relevant authorities. Any personal information will be handled in accordance with applicable laws and regulations.
Handling of Vulnerability Information
We do not recommend the public disclosure of detailed vulnerability information before appropriate remediation is available.
We support Coordinated Vulnerability Disclosure (CVD) and request that vulnerability details not be publicly disclosed until:
- A fix or mitigation has been released, or
- A reasonable period agreed upon by us and the reporter has elapsed.
As appropriate, we may publish:
- Security Advisories
- Information regarding security updates and fixes
- CVE identifiers
- Mitigation or workaround information
We may coordinate with CVE Numbering Authorities (CNAs) and obtain a Common Vulnerabilities and Exposures (CVE) identifier when appropriate.
The publication of acknowledgements or credits to reporters will be discussed and agreed upon on a case-by-case basis. Please note that we do not offer a reward or bounty program for vulnerability reports submitted in accordance with this policy.
Safe Harbor
For good-faith security research conducted in accordance with this policy, unless the purpose or manner of such activities is deemed unlawful or unjustified, we will treat such activities as authorized and permitted and will not pursue legal action against the reporter. If any legal action is initiated by a third party against the reporter for activities conducted in accordance with this policy, we will take reasonable steps to make it known that the reporter's actions were conducted in compliance with this policy.
Minimal testing necessary to verify a vulnerability for legitimate research purposes is permitted; however, we ask that researchers refrain from the following activities:
- Unauthorized use of systems or applications in a manner that causes or may cause damage to our company, our customers, or our business partners
- Physical attacks against our property (including infrastructure, facilities, and data centers)
- Accessing, retaining, or disclosing personal information or confidential information
- Testing for vulnerabilities through social engineering (such as phishing, vishing, or smishing) or other non-technical methods
- Any action that may place excessive load on our services, such as denial-of-service (DoS) attacks, or conduct stress tests or other activities that may cause service disruption
- Using other users' accounts, accessing customer environments, or modifying data
- Deploying ransomware, malware, or other malicious software
- Engaging in any unlawful activities
If, in connection with a vulnerability report, you obtain any personal information of our customers, business partners, employees, or other individuals, or any trade secret or confidential business information belonging to our company or any third party such as our customers or business partners, we ask that you promptly delete all such information (including, but not limited to, any logs) from all systems and devices in your possession or control.