Product security

Security is part of the product: our WBox gateways connect real installations, and we treat them accordingly. This page centralises our security contact, our coordinated disclosure policy and our security advisories.

Report a vulnerability

Think you have found a vulnerability in a WBox gateway, a Weble software product or this website? Write to security@weble.ch — describe the product and version, reproduction steps and estimated impact.

Our commitment (coordinated disclosure):

  • acknowledgement within 2 business days;
  • analysis, fix and publication coordinated with you;
  • no legal action against good-faith research;
  • public credit if you wish.

This contact point is also published in /.well-known/security.txt.

Security advisories

No vulnerability specific to Weble products has been published to date. We also track the third-party components we ship; the relevant public history of the VPN component is listed below.

October 2018 — VPN component (tinc ≤ 1.0.34)
CVE-2018-16758 (a man-in-the-middle could disable VPN packet encryption, CVSS 5.9), CVE-2018-16737 and CVE-2018-16738 (authentication-protocol weaknesses, CVSS 5.3 / 3.7). Fixed upstream in tinc 1.0.35 and 1.1.
Status: not affected — the Weble VPN infrastructure and up-to-date gateways run the 1.1 branch.
April 2013 — VPN component (tinc < 1.0.21, 1.1 < 1.1pre7)
CVE-2013-1428: stack buffer overflow exploitable by an already-authenticated peer (denial of service, possible code execution, CVSS 6.5). Fixed upstream in tinc 1.0.21 / 1.1pre7.
Status: fixed.
2002 — CVE-2002-1755 (tinc 1.0pre3/pre4)
Predates the first Weble gateways (2012) by a decade. Not affected.
Component — Node.js runtime
WBox gateways currently sold embed Node.js 18; migration to Node.js 22 (LTS) is planned. Earlier generations (Node.js 8) are no longer sold — contact us about upgrade options. The runtime serves the gateway’s web interface and the enabled protocol services (for example Modbus or BACnet servers) on the installation network. Upstream vulnerabilities are assessed against this context; an advisory is published here whenever a product is actually affected, together with the fix or workaround — rather than mirroring the raw upstream CVE feed, which would be unreadable and instantly stale.

Deployment recommendations

The network exposure of an automation gateway is managed first through architecture:

  • never expose a gateway directly to the Internet — neither the web interface nor the protocol services: Modbus and BACnet have no authentication by design;
  • segmented automation network (dedicated VLAN, firewall) for gateways and their devices;
  • remote access through the WBox VPN rather than port forwarding (NAT);
  • keep the firmware up to date.

Updates

Fixes are distributed through WBox gateway updates, deployable from the box interface or remotely over the VPN. We recommend keeping gateways up to date; documentation lives on wiki.weble.ch.

Secure by design

  • End-to-end encryption, peer-to-peer: your data never transits a third-party cloud;
  • local execution on the gateway — no middleware, no intermediate PC;
  • minimal Internet-facing exposure: outbound connections, no inbound port to open;
  • segmentation: topology and access rights defined by you, per site and per user.

Cyber Resilience Act (EU)

Weble is preparing for compliance with Regulation (EU) 2024/2847 (the “Cyber Resilience Act”). The obligations to notify actively exploited vulnerabilities and severe incidents apply since 11 September 2026; most remaining obligations apply from 11 December 2027. This page is the first building block: a single contact point, coordinated disclosure and public advisories. The support period of each gateway is stated on its product page (guaranteed at least until end of 2030); Weble software updates remain continuously available, and the system can be renewed by reflashing its storage (SD card or eMMC depending on the model).