10Evidence A

Vulnerabilities must be reported per regulations; no details, exploit tools, or disclosure to foreign entities before patching

The “Regulations on the Management of Security Vulnerabilities in Network Products” applies not only to companies but also to individuals. There are five strict rules for vulnerability disclosure; the first two state that no details about vulnerabilities affecting active systems may be released before a vendor provides a fix. Additionally, no programs or tools specifically designed to exploit those vulnerabilities may be published, and any release must include instructions on how to remediate them. One often-overlooked rule: unreported vulnerabilities must not be shared with any foreign organizations or individuals outside the vendor.

Cost

No cost involved. Simply report the vulnerability to the p…

Benefit

These regulations govern three main groups: domestic network product vendors, network operators, and any organ…

Cost

No cost involved. Simply report the vulnerability to the product vendor or an official platform. Until the vendor releases a patch, no details or verification code should be disclosed.

Benefit

These regulations govern three main groups: domestic network product vendors, network operators, and any organizations or individuals involved in discovering, collecting, or publishing vulnerability information. No entity may use vulnerabilities to compromise network security, nor may they illegally collect, sell, or distribute such information. Five additional rules apply to public disclosure: first, nothing may be released before a vendor provides a patch; second, no details about vulnerabilities in active networks or systems may be published; third, no exaggerated claims about risks or malicious exploitation attempts may be made; fourth, no tools or programs designed for malicious exploitation may be released; and fifth, any disclosure must include remediation steps. Unreported vulnerabilities must also not be shared with foreign entities. The regulations encourage reporting to four official platforms: the Ministry of Industry and Information Technology’s Cybersecurity Threat and Vulnerability Information Sharing Platform; the National Cybersecurity Information Notification Center’s Vulnerability Platform; the National Computer Network Emergency Response Technical Team/Coordination Center of China’s Vulnerability Platform; and the China Information Security Evaluation Center’s Vulnerability Database. Violators may face penalties ranging from fines of 10,000 to 100,000 RMB, suspension of services, revocation of licenses or business licenses, and even criminal liability for responsible personnel.

Original sources

工业和信息化部、国家互联网信息办公室、公安部 (2021). 网络产品安全漏洞管理规定(工信部联网安〔2021〕66 号,第二、四、九、十、十四条,2021 年 9 月 1 日施行). https://www.gov.cn/gongbao/content/2021/content_5641351.htm;全国人大常委会 (2025). 网络安全法(2025 年修正,2026 年 1 月 1 日施行,第二十八、六十五条;2016 年文本为第二十六、六十二条,规定第十四条援引的是 2016 年文本的条号). https://www.cac.gov.cn/2025-12/29/c_1768735112911946.htm

Open source link
Book note

This regulation explicitly includes individuals as subjects; claiming “I’m just an amateur” does not exempt anyone from compliance. Submitting vulnerabilities found in domestic systems to foreign bug bounty platforms violates the rule prohibiting disclosure to foreign entities. This rule addresses how vulnerabilities must be handled after discovery. Whether one is legally permitted to test systems depends on other provisions, such as the requirement for written authorization before testing any system. Even legally discovered vulnerabilities may incur penalties if disclosed improperly. Unauthorized testing results in violations on both fronts. Among reporting channels, the MIIT platform and CNCERT are most commonly used. The regulations do not specifically address cases where a vendor is notified but fails to act; in practice, documentation of negotiation and reporting processes is required before official submission.

My note