Control Plane & Policy
Protect the systems that authenticate operators and turn intent into network policy.
- Authentication or authorization bypass
- Cross-tenant administrative access
- Unauthorized policy, route, or configuration changes
Lushu Limited rewards original, responsibly disclosed vulnerabilities that demonstrate meaningful security impact in our SD-WAN platform, managed edge, and supporting network services.
Program scope
Valid reports in every area are eligible for payment after technical validation.
Protect the systems that authenticate operators and turn intent into network policy.
Preserve traffic confidentiality and isolation across sites, tenants, and overlays.
Secure managed edge nodes and the software path used to operate them at scale.
Rewards
We assess each verified report by severity, exploitability, affected scope, and report quality. Higher rewards are reserved for findings that cross trust boundaries, expose customer traffic, or enable control of multiple sites. Duplicate or previously known issues are not eligible.
Payment commitment
Every original report with validated security impact receives a monetary reward agreed after triage.
A useful report includes
Research rules
Test only systems and accounts you own or have explicit permission to use. Stop after proving impact. Do not retain customer data, degrade availability, perform denial-of-service testing, use social engineering, or access another customer's environment beyond the minimum evidence required.
Not eligible
Automated scanner output without validation, rate-limit observations without a security consequence, missing headers, self-XSS, third-party services outside Lushu's control, and findings that require physical access without crossing a defined trust boundary are out of scope.
Responsible disclosure
Send the report before public disclosure. We will acknowledge it, validate the impact, and coordinate remediation with you.