At Comcast, we’re committed to working alongside the security research community, and know we’re at our best when we continually enhance this process. That's why we’ve launched Xfinity Home’s bug bounty and expanded the scope to include Xfinity xFi. With your help, we continue with our mission to make Xfinity products more secure.
What is Xfinity Home?
Xfinity Home is a total home security solution that includes professional monitoring and advanced technology, all installed by experts and powered by WiFi from Xfinity.
What is xFi?
Xfinity xFi lets you manage your home WiFi network and connected home. You can self-install and set up your WiFi environment in minutes, find your WiFi password, know who's online, view camera video, troubleshoot issues and manage family members' online experiences with features like Pause and Parental Controls. xFi Advanced Security helps keep you safe on sites people visit, prevent remote access from unknown sources, and report/block suspicious device activity with real-time app notifications.
Please note, this program is specifically scoped for Xfinity Home and Xfinity xFi. If you believe you've found a security issue related to any other product or service(or are unsure) please report through our vulnerability disclosure program.
For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, in some cases, a vulnerability priority will be modified due to its attack complexity, requirements, likelihood, or impact of successful exploitation.
All submissions are reviewed to determine an accurate priority and any change will result in a detailed explanation provided to the researcher with the opportunity for a follow up.
Rewards are determined through an internal impact assessment, researcher interaction and the overall quality, content, and accuracy of the report
Rewards are determined through an internal impact assessment, researcher interaction and the overall quality, content, and accuracy of the report.
High impact findings
Comcast may reward eligible P1 submissions up to $10,000 for findings related to:
Remote unauthorized access (via publicly accessible internet, not on the same LAN/wireless network) of:
- Cloud storage videos
- Live camera feeds
Bypassing Armed Systems
Abuse/Theft of Service
Abuse/Theft of Service
Unauthorized access to WiFi credentials
Unauthorized access to Profile’s Active Time
Unauthorized access to Advanced Security settings or alerts
|VRT Name||Adjusted Priority|
|High Impact Subdomain Takeover||P2 -> P3|
|Basic Subdomain Takeover||P3 -> P4|
Scope and rewards
This program follows Bugcrowd’s standard disclosure terms.
For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email email@example.com. We will address your issue as soon as possible.
This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.