Security and compliance

Test Router A1

Test Manufacturing GmbH · TR-A1

Everything on this page is generated from the manufacturer's live product record. Last updated 27 Jul 2026, 11:02 UTC.

Security support until
30 June 2031

Article 13(8)

Components tracked
10

9 monitored continuously

Actively exploited, open
13

CISA KEV catalog

Supplier questionnaire

The clauses that come up in every OEM security questionnaire, answered here so you do not have to send an email and wait.

Do you maintain a software bill of materials, and will you provide it?

Yes. A software bill of materials is maintained for every release of Test Router A1 and is available on request in CycloneDX 1.6 and SPDX 2.3. The current SBOM was generated on 27 July 2026 and records 10 components, produced by binary analysis of the shipped firmware image. 9 of 10 components carry a public vulnerability identifier and are monitored continuously. The remaining 1 have no public identifier to match against and are listed on the trust page with the reason. Once attached to a release the SBOM is immutable, so the component list that shipped with a given version can always be reproduced.

Name the third-party and open-source components in the product.

The full list is in the SBOM. 10 components in the current release, including busybox 1.36.1, dnsmasq 2.78, dropbear 2019.78, linux_kernel 4.4.60, lwip 2.1.2, mbedtls 2.16.0, openssl 1.0.2n, realtek_sdk (version not recovered), u-boot 2016.11-rc2, zlib 1.2.11. Article 13(5) of Regulation (EU) 2024/2847 requires due diligence on third-party components, including open-source components not placed on the market commercially. Every component is monitored against the NVD, the CISA KEV catalog, the EU Vulnerability Database and the GitHub Advisory Database.

What is your timeline for notifying us of a vulnerability in the product?

A vulnerability with evidence of active exploitation is notified immediately, and in parallel we notify ENISA under Article 14(1) of Regulation (EU) 2024/2847 within 24 hours of becoming aware. Everything else is disclosed when the security update that fixes it ships, with a description, the affected versions, the impact and remediation guidance, as Annex I Part II point 4 requires. Notifications come from security@testmfg.example.

Do you operate a coordinated vulnerability disclosure policy?

Yes, as required by Annex I Part II point 5. It is published at https://testmfg.example/security. Reports go to security@testmfg.example, and the address is also served at /.well-known/security.txt. The policy carries a safe harbour commitment for good-faith research.

How long will the product receive security updates?

Security support for Test Router A1 runs until 29 June 2031. Article 13(8) sets a floor of five years, or the expected time in use where that is shorter. Separately, Article 13(9) requires every security update issued during the support period to remain downloadable for at least 10 years after it was issued, or for the rest of the support period if that is longer. The reasoning behind the date is recorded in the technical documentation under Annex VII point 4.

What is the product’s conformity status under the Cyber Resilience Act?

Test Router A1 is an important product, Annex III Class I under Regulation (EU) 2024/2847. The EU declaration of conformity is published on this trust page. The technical documentation required by Article 31 and Annex VII is maintained and retained for ten years.

Are there known unpatched vulnerabilities in the shipping version?

13 component vulnerability currently on the CISA Known Exploited Vulnerabilities catalog are open against this product and being worked. The VEX statements published on this page record the position on each one.

How are security updates delivered to devices in the field?

Signed image over HTTPS from update.testmfg.example, verified against a key fused into the bootloader, applied on reboot. Automatic by default with an opt-out in the web UI.

What is your process for reporting a security incident?

From 11 September 2026, a severe incident affecting the security of this product is notified to ENISA and the coordinating CSIRT through the Single Reporting Platform: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report one month after the full notification. The process is rehearsed against the published ENISA field set rather than written during an incident, and every action on a case is recorded in an append-only hash-chained log.

Which SBOM formats can you provide?

CycloneDX 1.6 and SPDX 2.3, both validated before release. VEX statements are provided in OpenVEX and CSAF 2.0. Component identification confidence and the evidence behind it travel as CycloneDX properties and SPDX package comments, so nothing is lost in export.

Reporting a vulnerability

Send reports to security@testmfg.example (Product Security).

The coordinated vulnerability disclosure policy is at https://testmfg.example/security.

Required by Annex I Part II points 5 and 6 of Regulation (EU) 2024/2847.

Vulnerability positions

Published VEX statements. A vulnerability in a component this product ships does not mean the product is exploitable, and this is where that is stated on the record rather than asserted in an email.

VulnerabilityStatusWhyUpdated
CVE-2014-0497Not affected
The vulnerable code is never executed
The affected subsystem is not built into this kernel configuration.
27 July 2026
CVE-2015-8651Affected
Action: Update to firmware 2.4.1 or later.
27 July 2026
CVE-2021-22555Not affected
The vulnerable code is never executed
The affected subsystem is not built into this kernel configuration.
27 July 2026

Machine-readable: OpenVEX · CSAF 2.0

Software bill of materials

10 components, generated 27 July 2026 by binary analysis of the shipped firmware image. Download as CycloneDX 1.6 or SPDX 2.3.

ComponentVersionTypeLicence
busybox1.36.1application
dnsmasq2.78application
dropbear2019.78application
linux_kernel4.4.60operating-system
lwip2.1.2library
mbedtls2.16.0library
openssl1.0.2nlibrary
realtek_sdknot recoveredlibrary
u-boot2016.11-rc2application
zlib1.2.11library
1 component without continuous monitoring

These have no public vulnerability identifier to match against, so a clean result for them means nothing was checked rather than nothing was found. Listed so the difference is visible.

  • realtek_sdk: No version was recovered from the image, so an affected-version range cannot be evaluated. Confirm the version from your build and set it.

Published by Test Manufacturing GmbH using CRA Kit. CRA Kit hosts this page and generates its contents from the manufacturer's data. The manufacturer is responsible for what it says.

Do you ship connected products into the EU? Find out where you stand in two minutes, free.