Melexis Security

A direct channel for researchers, customers, and third parties to report vulnerabilities or incidents in Melexis products and IT infrastructures.

Melexis Commitment

At Melexis, we recognise the paramount importance of safeguarding information and products. In today's interconnected world, where data drives innovation and sustains business operations, maintaining the confidentiality, integrity, and availability of our information assets is not just a goal but a fundamental responsibility.

As stewards of critical data, we declare our unwavering dedication to cyber security. We understand that protecting our information assets and securing our products is not only essential for our own success but also for the trust our clients, partners, and stakeholders place in us.

Reporting Guidelines: What to Report?

To ensure the Melexis security team receives actionable data and to minimize unrelated submissions, the webpage must clearly define what is in-scope and out-of-scope for product vulnerability reporting.

In-Scope Melexis Products Out-of-Scope / Exempted
Melexis integrated circuits (ICs), sensors, placed on the EU commercial market. Denial of Service (DoS) & Spam: Volumetric attacks, brute-force, or automated form submissions.
Standalone hardware developer and programming toolsets (e.g., Melexis PTC-05 programmer). Social Engineering & Phishing: Attacks targeting employees or users, or requiring improbable user interaction.
Embedded software, firmware, and ROM codes developed by Melexis. Information Disclosure: Software versions, path/stack traces, banner grabbing, or username enumeration.
Melexis internet-exposed assets, websites, and cloud assets. Best Practices & Security Headers: Missing HTTP security headers (HSTS, CSP, etc.), cookie flags on non-sensitive cookies, HTTPS mixed content, or weak CAPTCHA/password rules.
  Low-Impact Vulnerabilities: Unauthenticated CSRF, non-HTML content injection, or issues limited to outdated/EOL browsers and products.

Vulnerability reporting form

The data you enter in this form will be processed in order to comply with your request. For more information, please refer to our privacy policy.


Next steps after form submission

Upon submission through the web form or encrypted email to [email protected], the Melexis Security team will execute the following standard operational steps:

  1. Technical Triage & Acknowledgment
    Receipt is logged and a confirmation is sent to the reporter.
  2. Analysis and Impact Assessment
    The Melexis security team analyzes the report to verify exploitability and assess risk severity.
  3. Remediation & Patching
    Corrective patches or physical mitigations are engineered without undue delay.
  4. Coordinated Vulnerability Disclosure
    According to Melexis policy

PGP public key

To send an encrypted report by email, use the Melexis Security Office public PGP key. Verify the fingerprint before use.

Fingerprint A787 A292 7982 1E17 2E57 B431 8B48 AAE0 4816 EF7D
Email [email protected]

-----BEGIN PGP PUBLIC KEY BLOCK-----
mDMEap8KZhYJKwYBBAHaRw8BAQdAvHtMZU+XQFCMwkvC0OZAV0AxxBLX1J39nP2N
YYuJMey0NE1lbGV4aXMgU2VjdXJpdHkgT2ZmaWNlIDxzZWN1cml0eW9mZmljZUBt
ZWxleGlzLmNvbT6IkwQTFgoAOxYhBKeHopJ5gh4XLle0MYtIquBIFu99BQJqnwpm
AhsDBQsJCAcCAiICBhUKCQgLAgQWAgMBAh4HAheAAAoJEItIquBIFu99In8A/0a3
TyGCu2OMoXHabbNxeJwYtmERdoZXIhH53+bcGGAEAP9KAzTvxZvEmd/o/qMuLoeD
5EcZYrSZVGOM35MZ3bcjDbg4BGqfCmYSCisGAQQBl1UBBQEBB0D4osIYWC/YnZKE
f8PehUb8LnF61lj1DxCpPQGTxz+bYwMBCAeIeAQYFgoAIBYhBKeHopJ5gh4XLle0
MYtIquBIFu99BQJqnwpmAhsMAAoJEItIquBIFu99LIgA/1cBzy0SqnSrtU7AGVO6
Pi/ImJQoWw2W2mlwuX6I9o1CAQCBkx5YN/sIbyiEpdEQEgthJ2W2W0RZ6Y7d1QGP
8WAdAQ==
=ZSr9
-----END PGP PUBLIC KEY BLOCK-----

CVE Security Advisories

Melexis will publish formal security advisories for validated exploitable vulnerabilities only after a secure patch or remediation is available. Currently, no CVE exists related to Melexis products.