top of page

Product Security & Vulnerability Disclosure

1) Our commitment to product security

Buima Energy Co., Ltd. designs, manufactures and supports battery energy storage systems that contain software and connected components. We treat the cybersecurity of those components as a safety- and availability-critical property of the product, not an optional feature.

This page is our single public reference point for product security. It sets out how to report a suspected vulnerability to us, how we handle and disclose vulnerabilities, how we deliver security updates, and for how long we support each product. It is maintained to meet the vulnerability-handling and information duties placed on manufacturers by Regulation (EU) 2024/2847 (the Cyber Resilience Act, “CRA”), in particular Annex I Part II and Annex II, and is aligned with ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling processes).

2) Scope — products covered

This policy applies to all Buima Energy products with digital elements, and to the software and services we supply with them, including:

  • B.E.S.T. (Battery Energy Storage Tile) modular storage units and their enclosures
  • Battery Management System (BMS) firmware
  • Power conversion and charge-control firmware, including 400 VDC fast-charge control
  • Energy Management System (EMS) software and site controllers
  • Communication gateways and network interfaces (Modbus, CAN, Ethernet, Wi-Fi, cellular)
  • Cloud monitoring portal, APIs and mobile applications operated by Buima Energy
  • Over-the-air (OTA) update services and the tooling used to sign and distribute firmware

It also covers the Buima Energy corporate website and any third-party components integrated into the products above. Vulnerabilities in third-party components are handled under this policy, and we coordinate with the upstream supplier where a fix depends on them.

3) Reporting a vulnerability

Security contact (single point of contact): security@buimaenergy.com

Monitored on business days, Taipei time (UTC+8). Please use this address for security matters only — for sales, service and general enquiries use service@buimaenergy.com.

We welcome reports from customers, integrators, independent security researchers, CERT/CSIRT teams and regulators. You do not need a prior business relationship with us to report a vulnerability, and we do not require you to sign a non-disclosure agreement in order to submit a report.

What to include in your report

  • Affected product, model and firmware / software version (and hardware revision or serial number where relevant)
  • A description of the vulnerability and the security impact you believe it has
  • Step-by-step instructions to reproduce the issue, including any configuration or preconditions
  • Proof-of-concept code, scripts, packet captures, logs or screenshots, where available
  • Any CVE, CWE or CVSS assessment you have already prepared
  • Whether the issue is, to your knowledge, being actively exploited or is already public
  • How you would like to be credited, and your intended disclosure timeline if you have one
  • Your contact details and how you would prefer us to reach you

If your report contains sensitive technical detail, email us first and we will arrange a secure transfer channel before you send it.

Responsible testing — what we ask of you

Energy storage equipment is connected to live electrical infrastructure. When investigating, please:

  • Test only on equipment you own or for which the owner has given you explicit permission
  • Do not perform testing that could interrupt supply, damage hardware, create a fire or electrical hazard, or affect the safety of people or property
  • Do not access, modify, exfiltrate or delete data belonging to other customers, and stop immediately if you encounter personal data
  • Do not run denial-of-service, load, spam or social-engineering tests against our products, customers or staff
  • Give us a reasonable opportunity to remediate before disclosing publicly

Our commitment to you (safe harbour)

If you make a good-faith effort to comply with this policy, Buima Energy will treat your research as authorised, will not pursue or support legal action against you in relation to it, and will work with you to understand and resolve the issue quickly. If a third party brings action against you for activity conducted in accordance with this policy, we will make this authorisation known. We do not currently operate a paid bug bounty programme; we do offer public credit in our advisories where you wish to receive it.

4) Coordinated Vulnerability Disclosure (CVD) policy

We operate a coordinated disclosure model: we ask reporters to keep details confidential until a fix or mitigation is available, and in return we commit to fixing the issue promptly, keeping the reporter informed, and publishing an advisory.

  • Acknowledgement — within 3 business days. We confirm receipt of your report and assign it a tracking reference.
  • Triage and validation — within 10 business days. We attempt to reproduce the issue, determine affected products and versions, and assign a severity using CVSS v3.1 / v4.0.
  • Status updates — at least every 30 days. We tell you where remediation stands and give a target date for a fix.
  • Remediation — driven by severity. Critical and High issues are prioritised for an out-of-cycle security update. Where a fix will take longer, we publish an interim mitigation or workaround.
  • Coordinated disclosure — within 90 days of validation, or on release of the fix, whichever is sooner. We publish an advisory, request a CVE where appropriate, and credit the reporter unless anonymity is requested. We will agree an extension with you if a safe fix genuinely requires longer.
  • Actively exploited issues — immediate. We move to emergency handling, notify affected customers directly, and meet our regulatory reporting duties.

If a vulnerability is already public, or is being actively exploited, we may publish before the timeline above in order to protect users. We will always tell the reporter before we publish.

5) Security advisories

Once a security update or mitigation is available, we publish an advisory describing the vulnerability, the products and versions affected, its impact and severity, and the action users must take. Advisories are numbered BUIMA-PSA-YYYY-NNN.

No security advisories have been published to date.

When an advisory is published it will be listed here with its advisory ID, title, affected products, CVE reference, CVSS score, publication date and last-updated date.

Customers with a registered service contract are notified of new advisories by email. To be added to the notification list, contact security@buimaenergy.com.

6) Security updates

  • Free of charge. Security updates are provided at no cost for the duration of the support period, to all users of the affected product.
  • Separate from feature updates. Where technically feasible, security updates are issued independently of functionality updates, so that a security fix can be applied without accepting unrelated changes.
  • Authenticated and integrity-protected. Firmware and software images are cryptographically signed. Devices verify the signature before installation and reject unsigned or altered images. Updates are transported over authenticated, encrypted channels.
  • Delivered without delay. Once an update is available it is released promptly, together with an advisory message describing the issue and the action required.
  • Recoverable. Update mechanisms are designed to fail safely, retaining the previous working image so that a device can recover from an interrupted update.
  • User control. Where automatic updates are enabled by default, the product documentation explains how to review, defer or disable them, and what the security consequences of doing so are.

7) Support period and end of support

Buima Energy defines a support period for every product with digital elements. During that period we handle vulnerabilities effectively and supply security updates as described above.

  • Unless a longer period is stated in the product documentation or contract, the support period for Buima Energy energy storage products is 10 years from the date the individual unit is placed on the market.
  • The applicable end-of-support date is stated clearly at the time of purchase and is repeated in the product documentation delivered with the unit.
  • We publish end-of-support notices in advance of the date, together with guidance on migration, replacement or secure decommissioning.
  • After the end-of-support date we no longer guarantee security updates. Continuing to operate an unsupported unit on a network is at the operator’s own risk, and we recommend it be isolated or decommissioned.

Support period for a specific serial number: contact service@buimaenergy.com quoting the unit serial number.

8) Software Bill of Materials (SBOM)

We maintain a Software Bill of Materials for each product with digital elements, in a commonly used machine-readable format (CycloneDX or SPDX), covering at minimum the top-level dependencies of the product’s software. The SBOM is used internally to identify products affected by newly disclosed vulnerabilities in third-party components.

  • The SBOM is made available to market surveillance authorities on request, as required by the CRA.
  • Customers, integrators and asset owners may request the SBOM for a product they operate by emailing security@buimaenergy.com with the product model and firmware version.

9) Secure use, known risks and decommissioning

Full instructions are supplied with each product. The following measures are essential to operating a Buima Energy system securely.

At commissioning

  • Change all default credentials before the system is connected to any network.
  • Place the EMS, BMS and gateway on a segmented network (a dedicated VLAN or physically separate network). Do not expose control interfaces directly to the public internet.
  • Restrict inbound access to the minimum set of ports and management stations actually required, and disable interfaces and services you do not use.
  • Enable logging and, where available, forward logs to your own monitoring system.

Throughout the service life

  • Apply security updates promptly once released.
  • Review user accounts and access rights periodically and remove accounts that are no longer required.
  • Note that modifying the product, installing unapproved software, or bypassing safety and authentication controls can materially change its security and safety behaviour and may void warranty and conformity.

Known and foreseeable risks

  • Operating a unit past its end-of-support date without further security updates.
  • Connecting control or management interfaces directly to the internet, or leaving remote-access services enabled without authentication.
  • Retaining default or shared credentials, or reusing them across sites.
  • Using legacy fieldbus protocols (for example Modbus/TCP) on an untrusted network segment — these protocols provide no authentication by design and must be protected at the network layer.

Secure decommissioning

  • Before disposal, resale or return, perform the documented factory-reset and secure-erase procedure to remove configuration data, credentials, cryptographic keys and stored operating data.
  • Revoke the unit’s access to the Buima Energy cloud portal and remove it from your account.
  • Contact service@buimaenergy.com if you need the erase procedure for your model or written confirmation of data removal.

10) Regulatory reporting

For products made available on the EU market, Buima Energy reports actively exploited vulnerabilities and severe incidents affecting the security of its products to ENISA and to the CSIRT designated as coordinator, through the CRA single reporting platform, in accordance with Article 14 of Regulation (EU) 2024/2847:

  • Early warning — without undue delay and in any event within 24 hours of becoming aware
  • Vulnerability / incident notification — within 72 hours of becoming aware
  • Final report — within 14 days of a corrective measure becoming available (vulnerabilities), or within one month of the notification (incidents)

Where an actively exploited vulnerability or a severe incident affects the security of a product, we also inform the impacted users without undue delay, and where necessary tell them what corrective action they should take.

These reporting obligations under the CRA apply from 11 September 2026; the remaining obligations apply from 11 December 2027. Buima Energy is operating to this policy in advance of those dates.

11) Standards and regulatory framework

  • Regulation (EU) 2024/2847 — Cyber Resilience Act (Annex I Parts I & II; Annex II)
  • ISO/IEC 29147 — Information technology — Security techniques — Vulnerability disclosure
  • ISO/IEC 30111 — Information technology — Security techniques — Vulnerability handling processes
  • CVSS v3.1 / v4.0 — Common Vulnerability Scoring System, used for severity rating
  • IEC 62443 — Security for industrial automation and control systems, in particular 62443-4-1 (secure development lifecycle) and 62443-4-2 (component requirements)
  • FIRST PSIRT Services Framework — reference model for our product security incident response process

12) EU Declaration of Conformity and CE marking

Buima Energy products placed on the EU market bear the CE marking and are accompanied by an EU Declaration of Conformity. A copy is supplied with the product, and further copies are available on request from service@buimaenergy.com.

13) Manufacturer contact details

  • Manufacturer: Buima Energy Co., Ltd.

  • Registered office: 13F., No. 880, Zhongzheng Rd., Zhonghe Dist., New Taipei City 235, Taiwan

  • Operations: 13F., No. 880, Zhongzheng Rd., Zhonghe Dist., New Taipei City 235, Taiwan

  • Security contact: security@buimaenergy.com — vulnerability reports and coordinated disclosure

  • General contact: service@buimaenergy.com · +886-2-2508-0656

  • Website: www.buimaenergy.com

14) Changes to this policy

We review this policy at least annually and whenever our products, processes or the applicable regulatory framework change materially. The current version is shown below.

Version 1.0 · Effective 3 September 2026 · Last reviewed 3 September 2026

bottom of page