Product security

Report a security vulnerability or product weakness at Carl Valentin

This is the central reporting channel for customers, partners and security researchers to report possible security vulnerabilities in printing systems, firmware, software and digital interfaces from Carl Valentin. One click is enough to start a report – even if you are not yet sure whether a security issue really exists. We review every report carefully and treat security-relevant information confidentially.

  • Welcome even when you are unsure
  • Report in German or English
  • Confidential handling

Report a security-relevant issue

For possible security vulnerabilities, product weaknesses or security-relevant incidents in products and digital components from Carl Valentin. Ideally use the subject pattern Security report – Product – Short description.

Open email with subject

What is this reporting channel for?

Use this contact point to report security-relevant observations regarding products, software and digital components from Carl Valentin.

Products and components

You can submit reports for these solutions

  • Label printers
  • Direct print engines and print modules
  • Print & Apply systems
  • Touch panels and control components
  • Firmware, software and printer drivers
  • Configuration tools as well as network and communication interfaces
Examples

Typical security-relevant observations

  • Unauthorised access or bypassing of a login
  • Unintended escalation of user privileges
  • Disclosure or modification of data
  • Execution of unauthorised program code
  • Insecure update, authentication or communication methods
  • Indications of active exploitation or a security incident

Which details help us assess your report?

The more comprehensible your report, the faster we can triage it. The essentials are shown below at a glance; the copyable template beneath contains all fields. Only fill in what you have; you can attach screenshots or logs.

The essentials at a glance

  • Product, version and affected component
  • Description of the observation
  • Steps to reproduce
  • Possible impact
  • Indications of active exploitation
  • Contact option for follow-up questions
Copyable template for your email
Subject: Security report – [Product] – [Short description]

Product (e.g. ILX V, Vario V):
Serial number (if shown on the type plate):
Firmware, software or driver version:
Affected component / interface:
Technical environment / configuration:

Description of the observation:

Observed or possible impact:

Steps to reproduce:

Indications of active exploitation:

Already published or reported to third parties?:

Contact for follow-up questions:
Named credit desired: Yes / No

How we handle your security report

Scope, technical complexity and risk can vary from report to report. The following steps outline the basic path from intake to coordinated communication of possible measures.

Intake and registration

We register the report and assign it to the responsible departments. If details are missing, we contact you where a contact option is available.

Technical assessment

We examine the described observations, try to reproduce them and assess exploitability, reach and possible impact.

Measures

If a vulnerability is confirmed, we evaluate suitable measures such as updates, configuration guidance or temporary safeguards.

Coordinated communication

Further communication is coordinated so that affected users receive appropriate information and safeguards as promptly as possible.

Responsible Disclosure: reporting responsibly

We value the support of customers, partners and independent security researchers. The following rules help investigate possible product weaknesses without unnecessarily endangering customers, systems, data or production processes.

Please do

  • Report findings to Carl Valentin confidentially first
  • Only test systems and products you are authorised for
  • Limit testing to what is necessary for proof
  • Allow sufficient time for investigation and remediation
  • Coordinate any publication of technical details in advance
  • Stop testing and inform us if you encounter confidential data

Please avoid

  • Accessing third-party data, accounts or production systems
  • Modifying, deleting or sharing data
  • Denial-of-service attacks or load tests on production systems
  • Social engineering, phishing or physical attacks
  • Installing persistent access, malware or backdoors
  • Publicly sharing technical details without prior coordination

Cyber Resilience Act and product security

The European Cyber Resilience Act (CRA) strengthens the cybersecurity requirements for products with digital elements. If a report indicates an actively exploited vulnerability or a severe security incident, Carl Valentin checks whether statutory reporting obligations apply and submits any required notifications through the designated channels.

The CRA reporting obligations for manufacturers apply from 11 September 2026. They include an early warning within 24 hours and a further notification within 72 hours of becoming aware of a reportable event. These deadlines concern notifications by the manufacturer to the competent authorities. They are not a blanket assurance that every externally submitted report can be fully assessed or remediated within these times.

Further information is available from the European Commission on the CRA reporting obligations (opens in a new window) .

Frequently asked questions about reporting security vulnerabilities

Select a question to open the answer.

What is the difference between a security vulnerability and a technical fault?

A security vulnerability may, for example, enable unauthorised access, the disclosure or modification of data, an escalation of privileges or the bypassing of protective mechanisms. An ordinary technical fault, by contrast, affects function or operation without any recognisable security aspect. Send security-relevant reports to security@carl-valentin.de, and pure faults to support@carl-valentin.de.

Can I report anonymously or under a pseudonym – and will I be named?

You may use a pseudonym for communication. A reachable contact option is nevertheless helpful so that we can raise technical questions and keep you informed about key developments. You will only be named after prior coordination and with your consent – simply let us know in your report whether you would like to be credited or remain anonymous.

May I publish a vulnerability I have discovered?

Please coordinate any publication of technical details with Carl Valentin in advance. This allows us to investigate the report and provide affected users with updates or safeguards in good time before details become public.

Is this a bug bounty programme? Will I receive a reward?

This reporting point is not a bug bounty programme. A report does not, in principle, give rise to any automatic entitlement to remuneration. Any deviating arrangements require prior written confirmation.

Last updated: July 2026

CARL VALENTIN GMBH ·
Neckarstraße 78 - 86 u. 94 ·
78056 Villingen-Schwenningen

Tel. +49 7720 9712-0 ·
Distribution centre +49 7720 9712-20 ·
info@domain1.tld