This program encourages and rewards contributions by developers and security researchers who help make Arlo’s products more secure. Arlo provides monetary rewards and kudos for qualifying vulnerability submissions to this program. For submissions outside the scope of this program Arlo rewards Kudos points. Please click on the following link to the Arlo Kudos Rewards Program.
NETGEAR products have their own Bug Bounty program. Please click the following link to NETGEAR Cash Rewards Program.
Only vulnerabilities found in the latest version of the above are eligible. Targets listed below denote Cloud Infrastructure that support in-scope devices and are included in scope:
A note about business impact
arlo appreciates the efforts and contributions from the security research community. In order to provide researchers with timely and accurate rewards, arlo requests that submitters include a statement about perceived impact to arlo, along with the submission details. Not only will this help arlo reproduce, rate and reward your findings in a timely manner --- it is likely to help improve the severity score of your finding as well!
This program follows Bugcrowd’s standard disclosure terms.
For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.
This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.
Scope Type | Scope Name |
---|---|
android_application | Arlo Android App |
api | myapi.arlo.com |
ios_application | Arlo iOS App |
undefined | Arlo Security Light |
undefined | Arlo Bridge |
undefined | Arlo Pro 3 |
undefined | Arlo Pro 2 |
undefined | Arlo Pro |
undefined | Arlo |
undefined | Arlo Base Station |
undefined | Arlo Ultra |
undefined | Arlo Go |
undefined | Arlo Q |
undefined | Arlo Q+ |
undefined | Arlo Baby |
undefined | Arlo Video Doorbell |
undefined | Arlo Floodlight |
undefined | Arlo Essential |
undefined | Arlo Wireless Video Doorbell |
web_application | https://arlo-device.messaging.netgear.com/ |
web_application | http://shop.arlo.com/ |
web_application | https://arlo-device.messaging.netgear.com |
web_application | https://updates.netgear.com/arlo |
web_application | https://my.arlo.com |
web_application | https://www.arlo.com |
The progam has been crawled by Firebounty on 2018-05-29 and updated on 2020-04-23, 96 reports have been received so far.
FireBounty © 2015-2024