store.logitech.com.cn is a hosted 3rd party service, so we will forward any reports onto the vendor.
This domain is for a legacy product. We will accept reports, but resolving times may be long for lower priority issues as there are limited customer's still using it.
Only the sections of www.logitech.com that deal with Logitech Accounts. This is typically anything accessed once you click My-Account and login, or create an account.
This is Sync Desktop Application by Logitech. The latest version is eligible.
Other logitech websites not explicitly listed
Ineligible for bounty:
store.logitech.com.cn is a hosted 3rd party service, so we will forward any reports onto the vendor.
This domain is for a legacy product. We will accept reports, but resolving times may be long for lower priority issues as there are limited customer's still using it.
Please note exploits resulting from physical hacks to the device itself are out of scope, and any received reports will be marked N/A in accordance with HackerOne policy. Please refrain from submitting reports for physical hacks to avoid losing Reputation.
At this time we are unable to provide Circle devices for testing purposes. If you already own a Circle , hack away to your heart's content, otherwise watch this space for updates!
Eligible models include all Circle cameras (Circle View Doorbell, Circle View Camera, Circle 2, Circle) running the latest firmware.
The latest version is eligible
Also includes: vcp-external.logitech.com and external-qa.logitech.com
App: BOOM & MEGABOOM by Ultimate Ears
Logitech Options software lets you customize your Logitech device.
The latest version is eligible (PC & MAC).
Are in the scope:
admin.getmeetio.com
storage.getmeetio.com
stats-api.getmeetio.com
api.getmeetio.com
look.getmeetio.com
parse.getmeetio.com
The service hosted on buy.logitech.com is provided by a 3rd party called Digital River. We will forward reports to them.
This app is Streamlabs Deck by Streamlabs
Logi Tune Desktop application for PC and MAC reports are eligible as long as they are on the latest version.
In-scope devices: R500 Laser Presentation Remote; Spotlight Presentation Remote; R400 Laser Presentation Remote; R700 Laser Presentation Remote
Also includes jira.logitech.io
This App is Logi Tune for Zone Headsets by Logitech
All products running their latest firmware listed in the page below are eligible:
https://www.logitech.com/en-us/video-collaboration/products
This is the "Streamlabs: Live Streaming" App by Streamlabs
If you have a question about something that is not explicitly listed (or falls under a wildcard domain), please submit a report and we will provide clarification. We will allow you to self close that report after we answer your question.
The current generation of Logitech Keyboards and Mouses.
App: BOOM & MEGABOOM by Ultimate Ears
The Harmony Desktop software for PC / MAC.
This app is part of the Circle ecosystem of camera devices.
Cloud service associated with the Logitech Sync application
Only the latest version of GHub is in scope.
Other logi.com domains not explicitly listed.
Logi Options+ software lets you configure your Logitech device.
The latest version is eligible (PC & MAC).
This app is Logi Tune by Logitech Inc.
Are in the scope:
Meetio Room (com.getmeetio.room), Android
Meetio View (com.getmeetio.view), Android
Meetio Desk (com.getmeetio.meetiodesk), Android
Meetio Update (com.getmeetio.update), Android
Meetio System (com.getmeetio.system), Android
Meetio Personal (com.getmeetio.personal), Android
Are in the scope:
admin.getmeetio.com
storage.getmeetio.com
stats-api.getmeetio.com
api.getmeetio.com
look.getmeetio.com
parse.getmeetio.com
This domain is for a legacy product. We will accept reports, but resolving times may be long for lower priority issues as there are limited customer's still using it.
This covers all Logitech Desktop and Mobile applications not specifically defined by other assets.
This domain is for a legacy product. We will accept reports, but resolving times may be long for lower priority issues as there are limited customer's still using it.
This is the iOS app for the Circle ecosystem of devices,
Other domains under logitech.io not explicitly listed.
Meetio Personal (com.getmeetio.Meetio-Enterprise), iOS
Also includes the *.video.logi.com and *.circle.logi.com
See developer documentation at https://developers.logitech.com/circle
Other current generations Hardware/IoT devices not explicitly listed in the asset list.
Logitech Security Team might reward a report up to their discretion.
Squeezebox products were EOL'ed many years ago and aren't eligible for submissions.
Logitech Alert cameras and the Commander software were EOL'ed many years ago and are not in scope for submission.
In scope products: Harmony Elite, Harmony 950, Harmony Companion, Harmony Hub, Harmony 665, Harmony 350 Control.
Products in scope are the current generation
BLAST, MEGABLAST, BOOM 3, MEGABOOM 3, WONDERBOOM 2, HYPERBOOM, POWER UP
Non production testing site exists under sandbox.accounts.logi.com
This app is Streamlabs: Stream Live by Streamlabs