Product security
Report a security vulnerability or product weakness at Carl Valentin
This is the central reporting channel for customers, partners and security researchers to report possible security vulnerabilities in printing systems, firmware, software and digital interfaces from Carl Valentin. One click is enough to start a report – even if you are not yet sure whether a security issue really exists. We review every report carefully and treat security-relevant information confidentially.
- Welcome even when you are unsure
- Report in German or English
- Confidential handling
Report a security-relevant issue
For possible security vulnerabilities, product weaknesses or security-relevant incidents in products and digital components from Carl Valentin. Ideally use the subject pattern Security report – Product – Short description.
security@carl-valentin.de Open email with subjectWhat is this reporting channel for?
Use this contact point to report security-relevant observations regarding products, software and digital components from Carl Valentin.
You can submit reports for these solutions
- Label printers
- Direct print engines and print modules
- Print & Apply systems
- Touch panels and control components
- Firmware, software and printer drivers
- Configuration tools as well as network and communication interfaces
Typical security-relevant observations
- Unauthorised access or bypassing of a login
- Unintended escalation of user privileges
- Disclosure or modification of data
- Execution of unauthorised program code
- Insecure update, authentication or communication methods
- Indications of active exploitation or a security incident
Which details help us assess your report?
The more comprehensible your report, the faster we can triage it. The essentials are shown below at a glance; the copyable template beneath contains all fields. Only fill in what you have; you can attach screenshots or logs.
The essentials at a glance
- Product, version and affected component
- Description of the observation
- Steps to reproduce
- Possible impact
- Indications of active exploitation
- Contact option for follow-up questions
Subject: Security report – [Product] – [Short description] Product (e.g. ILX V, Vario V): Serial number (if shown on the type plate): Firmware, software or driver version: Affected component / interface: Technical environment / configuration: Description of the observation: Observed or possible impact: Steps to reproduce: Indications of active exploitation: Already published or reported to third parties?: Contact for follow-up questions: Named credit desired: Yes / No
How we handle your security report
Scope, technical complexity and risk can vary from report to report. The following steps outline the basic path from intake to coordinated communication of possible measures.
Intake and registration
We register the report and assign it to the responsible departments. If details are missing, we contact you where a contact option is available.
Technical assessment
We examine the described observations, try to reproduce them and assess exploitability, reach and possible impact.
Measures
If a vulnerability is confirmed, we evaluate suitable measures such as updates, configuration guidance or temporary safeguards.
Coordinated communication
Further communication is coordinated so that affected users receive appropriate information and safeguards as promptly as possible.
Responsible Disclosure: reporting responsibly
We value the support of customers, partners and independent security researchers. The following rules help investigate possible product weaknesses without unnecessarily endangering customers, systems, data or production processes.
Please do
- Report findings to Carl Valentin confidentially first
- Only test systems and products you are authorised for
- Limit testing to what is necessary for proof
- Allow sufficient time for investigation and remediation
- Coordinate any publication of technical details in advance
- Stop testing and inform us if you encounter confidential data
Please avoid
- Accessing third-party data, accounts or production systems
- Modifying, deleting or sharing data
- Denial-of-service attacks or load tests on production systems
- Social engineering, phishing or physical attacks
- Installing persistent access, malware or backdoors
- Publicly sharing technical details without prior coordination
Cyber Resilience Act and product security
The European Cyber Resilience Act (CRA) strengthens the cybersecurity requirements for products with digital elements. If a report indicates an actively exploited vulnerability or a severe security incident, Carl Valentin checks whether statutory reporting obligations apply and submits any required notifications through the designated channels.
The CRA reporting obligations for manufacturers apply from 11 September 2026. They include an early warning within 24 hours and a further notification within 72 hours of becoming aware of a reportable event. These deadlines concern notifications by the manufacturer to the competent authorities. They are not a blanket assurance that every externally submitted report can be fully assessed or remediated within these times.
Further information is available from the European Commission on the CRA reporting obligations (opens in a new window) .
Frequently asked questions about reporting security vulnerabilities
Select a question to open the answer.
What is the difference between a security vulnerability and a technical fault?
A security vulnerability may, for example, enable unauthorised access, the disclosure or modification of data, an escalation of privileges or the bypassing of protective mechanisms. An ordinary technical fault, by contrast, affects function or operation without any recognisable security aspect. Send security-relevant reports to security@carl-valentin.de, and pure faults to support@carl-valentin.de.
Can I report anonymously or under a pseudonym – and will I be named?
You may use a pseudonym for communication. A reachable contact option is nevertheless helpful so that we can raise technical questions and keep you informed about key developments. You will only be named after prior coordination and with your consent – simply let us know in your report whether you would like to be credited or remain anonymous.
May I publish a vulnerability I have discovered?
Please coordinate any publication of technical details with Carl Valentin in advance. This allows us to investigate the report and provide affected users with updates or safeguards in good time before details become public.
Is this a bug bounty programme? Will I receive a reward?
This reporting point is not a bug bounty programme. A report does not, in principle, give rise to any automatic entitlement to remuneration. Any deviating arrangements require prior written confirmation.
Last updated: July 2026