【 Taipei, Taiwan 】
CTOne today announced that it has been authorized by the Common Vulnerabilities and Exposures (CVE®) Program as a CVE Numbering Authority (CNA). The mission of the CVE Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.
The CVE Program is a global, community-driven initiative dedicated to identifying and documenting cybersecurity vulnerabilities. Discovered vulnerabilities are assigned unique identifiers and published in the CVE List by CNAs.
CNAs are organizations responsible for the regular assignment of CVE IDs to vulnerabilities and for creating and publishing information about the vulnerabilities in the associated CVE Record. Each CNA has a specific scope of responsibility for vulnerability identification and publication.
CTOne’s TR2 (Threat Research and Response) team contributes to this effort as a dedicated threat and attack intelligence team, delivering in-depth cybersecurity knowledge and expertise. TR2 helps enterprises strengthen the overall security posture of private wireless deployments, specializing in private cellular networks and addressing threats in packet core, RAN, and cellular IoT devices.
TR2’s scope includes vulnerabilities in cellular (LTE/4G/5G) devices and protocols, covering cellular infrastructure components such as packet-core elements (EPC, 5GC) and RAN nodes (gNB, eNB, ORAN). Additionally, TR2 addresses vulnerabilities in cellular IoT (CIoT) devices, which include IoT devices with a cellular interface, such as sensors, routers, cameras, and drones. Our focus also extends to protocol vulnerabilities in Communication Technology (CT) protocols, including GTP, NGAP, PFCP, E2AP, and F1AP, across various devices.
Submit discovered vulnerabilities: [email protected]
For more details: CTOne Vulnerability Disclosure Policy
As a CVE Program partner, CTOne will continue to assist researchers and vendors in the responsible disclosure of reported vulnerabilities, working toward a more secure mobile world for all.