Product Security

This page is where vulnerabilities in Segway-Ninebot products with digital elements can be reported, and where we publish vulnerability information. We work with external security researchers to improve the overall security of our products, and provide security advisories and support-period information to keep users informed and safe.

Coordinated Vulnerability Disclosure Policy

Version 1.0 · Effective 2026-09-01 · Maintained by the Segway-Ninebot PSIRT
Scope.All Segway-Ninebot products with digital elements placed on the market, including embedded software, mobile applications and remote data processing solutions related to these products.

Segway-Ninebot products with digital elements include: electric kickscooters, self-balancing vehicles, eBikes, Navimow robotic mowers, and their software and mobile applications.

Report a Vulnerability

Please use the following channels to report suspected security vulnerabilities in our products, applications, or related services.

PGP Public Key

Please report security vulnerabilities primarily via the email address. If email is not convenient, you may also report through the customer service channels in your country or region; your report will be forwarded to our Product Security Incident Response Team (PSIRT).

Anonymous reports are accepted. However, providing contact information helps usvalidate the issue and coordinate remediation.

How We Handle Reports

Upon receipt of a report, we review the information provided to determine whether it contains sufficient detail for assessment, verify whether the report identifies a valid security vulnerability, assess its severity and potential impact, identify affected products or versions, and determine appropriate remediation measures.

How to report.Email product-security@ninebot.com with the product name and software version, a description of the vulnerability and steps to reproduce it, and — if known — whether it is public or actively exploited. Anonymous reports are accepted. Where sensitive details are involved (exploit code, customer data, keys, configuration data), we recommend encrypting them with our PGP public key; where convenient, please include your own PGP key so that we can share sensitive information with you securely.

What to Include in Your Report

To help us assess and reproduce the issue, please include as much of the following information as possible:

•  Product name and model

•  Affected software, firmware, or app version

• Detailed description of the vulnerability

• Step-by-step reproduction instructions

• Expected and actual behavior

• Potential impact

• Proof-of-concept code, screenshots, logs, or network traces, if available

• Your name and contact information (optional for anonymous reports)

• if known-whether it is public or actively exploited

What to expect.We will stay in contact with you throughout the process: we acknowledge your report within 3 business days, provide an initial assessment within 10 business days, and notify you once the vulnerability has been remediated, mitigated, or otherwise closed. We may also share further updates where appropriate, including if there are adjustments to the remediation plan, changes to the disclosure timeline, or delays resulting from coordination with relevant third parties. Vulnerabilities are remediated without undue delay; security updates are provided free of charge.

Coordinated Disclosure and Embargo Period

Confirmed vulnerabilities may be handled under a coordinated disclosure process, especially where a fix is not yet available, where remediation requires coordination across multiple affected products or parties, or where third-party, open-source, or

supplier-provided components are involved. Unless otherwise agreed, the default embargo period is 90 business days from confirmation of the

vulnerability. This period may be adjusted case by case depending on remediation complexity, supply chain coordination, and the security risk involved. During the embargo period, vulnerability details should not be publicly disclosed before remediation or an advisory is available. After remediation, we may publish relevant information through our Security Advisories and, where appropriate, also share vulnerability information with the EU Vulnerability Database (EUVD).

Good-faith research. Research conducted in good faith under this policy is authorized: do not access others' data, do not degrade the availability or safety of products in use, comply with applicable law. Segway-Ninebot will not initiate legal action for research conducted in accordance with this policy.

Acknowledgement and recognition.

With your consent, we will acknowledge your contribution in our security advisory or on our acknowledgments page.

Security Advisories

Published after a security update or corrective measure is available. Each advisory describes the vulnerability and its severity, affected versions, and how to obtain and install the fix.

* Severity is scored using CVSS v3.1 — see the CVSS v3.1 Specification Document.

IDTITLECVSSPublished DateSecurity Advisory

Security updates are delivered over-the-air via the Segway-Ninebot / Navimow app and installed automatically by default (opt-out available in app settings). Each released update remains available for at least 10 years or the remainder of the support period, whichever is longer.

Support Period

The support period is the period during which vulnerabilities are handled effectively and security updates are provided — at least 5 years. The end date is also indicated on each product page at the time of purchase.

ModelSupport Period Ends (No Earlier Than)

i105E,i108E

2034-12

X315E,X330E,X350E,X390E

2032-12

MH2206E,MH2210E,MH2215E,MH2230E

2032-12

Mi2808E,Mi2810E,Mi2815E,Mi2820E

2032-12

Mi2705E,Mi2706E,Mi2708E,Mi2710E

2033-12

MX2220E,MX2230E,MX2250E,MX22A0E,MX22B4E

2034-12

Mi2910,Mi2920E

2032-02

Mi3208E,Mi3708E,Mi3710E

2035-12

MZ5210E,MZ5410E,MZ5420E,MZ5430E

2033-12

MH5210E,MH5410E,MH5420E

2033-12