Skip to content

One answer from the factory. Every brand covered.

VexRoute is the vulnerability channel between ODM factories in China and the EU brands they supply. When a CVE hits a shared chipset or SDK, the factory answers once and every affected brand gets that answer, mapped to its own SKUs, with the CRA clock already running.

CRA reporting obligations have applied since 11 September 2026, including to products already on the market.

One factory answer routed to every brandA factory in Shenzhen sends one vulnerability answer to VexRoute, which routes it to seven European brands selling different products built on the same firmware.ODM factoryShenzhenanswers onceVexRouteSmart camerasAmsterdamCamerasKids' smartwatchesLyonWatchesPet trackersMunichTrackersAndroid TV boxesMadridTV boxes5G routersMilanRoutersHome sensorsStockholmSensorsWearablesWarsawWearables
Illustrative: the brands shown are product categories, not customers.

Your products are built in Shenzhen. Your reporting deadline is set in Brussels.

Most connected electronics sold by European brands, from smart cameras and kids' watches to pet trackers, TV boxes and 5G routers, run firmware written by an ODM in Guangdong. Often it sits on a shared platform or chipset SDK that dozens of other brands also use.

So when a vulnerability lands in that chipset, every brand asks the same factory the same question at the same time: are we affected, which SKUs and firmware, and is there a fix?

The questions arrive in a generic sales inbox, in different languages and formats, six or seven hours out of sync. Nobody on either side owns the answer. It takes days. The CRA gives you 24 hours.

Read the full problem

sales@factory-example.cn

23 unread

  • Brand in Amsterdam

    09:12 CET

    Are our cameras affected by the new Wi-Fi chipset CVE? Legal needs an answer today.

  • Brand in Lyon

    09:40 CET

    Please fill in the attached spreadsheet for every SKU you supply to us.

  • Importer in Munich

    10:05 CET

    Which firmware versions are we running? Is there a patch date?

  • Brand in Madrid

    11:30 CET

    Re: Re: Fwd: urgent security question, see thread below

  • Brand in Warsaw

    13:15 CET

    Our CRA consultant says we must report within 24 hours. Please confirm status.

  • Brand in Milan

    16:50 CET

    Following up again. Is anyone on your side handling this?

同一个问题,二十三种格式。工厂在深圳时间晚上才看到。The same question in twenty-three formats. The factory sees it in the Shenzhen evening.

Illustrative: one chipset advisory, one factory, every brand asking at once.

How VexRoute works

Four steps. The first two happen once, before anything goes wrong. The last two happen every time a vulnerability hits.
  1. Step 1: Map your products

    Link each SKU to the firmware family it runs and the ODM behind it. Shared firmware becomes visible across your whole catalogue.
  2. Step 2: Connect your factories

    Each ODM gets a bilingual Chinese and English workspace. They see the firmware families their customers rely on, nothing more.
  3. Step 3: Ask once, answer once

    When a CVE lands, one structured question goes to the factory. They answer per firmware family: not affected, affected, fixed or under investigation.
  4. Step 4: Route and report

    Every linked brand receives the answer against its own SKUs, with the CRA clock started and an ENISA reporting packet pre-filled for review.

See the platform in detail

When a CVE drops, have the answer before the clock runs out.

The CRA's early warning is due 24 hours after you become aware of an actively exploited vulnerability. A forwarded email chain can't meet that. A routed answer can.

Without a channel

Twenty brands email a sales inbox in different formats and time zones.

  1. 0 hChipset CVE is published
  2. 15 hSales forwards it to R&D
  3. 38 h“Still checking, which SKUs?”
  4. 54 hBrand resends its product list
  5. Answer arrives day 6 or later

With VexRoute

One bilingual question to the factory. One answer, routed to every brand.

  1. 0 hChipset CVE is published
  2. 8 hODM answers once, per firmware family
  3. 19 hEarly-warning packet ready to review
  4. 52 h72-hour notification drafted with the fix

Deadlines: early warning at 24 hours, notification at 72 hours.

An illustrative timeline, not measured data. Real timings depend on the vulnerability and the factory. The legal deadlines are fixed: 24 hours for the early warning, 72 hours for the notification.

Between incidents, the evidence keeps building.

Every question asked and every answer given is kept, with timestamps, against the SKU and firmware family it concerns. When a retailer, tender, auditor or Notified Body asks how you handle vulnerabilities, you show them.
Illustrative evidence trail: each SKU linked to a firmware family, its ODM, and the latest VEX status
SKUFirmware familySupplierVEX statusLatest answer
CAM-210Indoor cameraIPC-T31 v4.2ODM A, ShenzhenFixedFirmware 4.2.7 shipped
CAM-220Doorbell cameraIPC-T31 v4.2ODM A, ShenzhenFixedSame family, same answer
SEN-04Door sensorZB-Lite 2.xODM B, DongguanNot affectedChipset not used
PLG-11Smart plugWB3S-Plug 1.9ODM C, ZhongshanUnder investigationAnswer due in 6 h
HUB-01Home hubLinux-GW 5.1ODM A, ShenzhenAffectedMitigation published
Illustrative data. Two cameras share one firmware family, so one factory answer covers both.

Ready when someone asks

  • Retailer and marketplace security questionnaires
  • Public and enterprise tender requirements
  • Internal audits and market surveillance requests
  • Notified Body and conformity assessment evidence
  • Supplier changes, firmware updates and end-of-support dates

What we handle all year

Built for both ends of the route, and the people advising them.

EU brands and importers

You sell it under your name, so the CRA treats you as the manufacturer.

Product, compliance and purchasing teams get one place to ask the factory, see which SKUs are affected and pull a reporting packet in hours, not weeks.

VexRoute for brands

ODMs and OEMs in China

Answer once. Stop filling in fifty spreadsheets.

A bilingual workspace for your R&D and sales teams. Answer per firmware family and every linked EU customer gets the answer, mapped to their own products.

VexRoute for factories

CRA consultants and sourcing agents

You own the advice. We run the pipe underneath it.

Give your clients a working ODM channel and an evidence trail that stands up in audits, without becoming their supplier-chasing department.

Partner with VexRoute

Why VexRoute

One answer per firmware family
Brands that ship the same firmware get the same answer from the same source, at the same time. The factory does the work once.
Bilingual where it matters
The factory side works in Chinese and English, so the R&D engineer who knows the answer can give it directly, without a sales relay.
Evidence, not just alerts
Answers become a timestamped trail tied to SKUs, firmware, suppliers, VEX statements and SBOMs. That's what auditors and procurement teams ask for.
Under your consultant, not instead
CRA consultants keep the advice, process and audit readiness. VexRoute runs the ODM channel and the evidence pipe beneath their work.
Priced by what you track
Firmware families and supplier connections, not incidents. A bad week of CVEs never shows up on your invoice.

The CRA, on one line

Reporting is already live. The rest of the regulation lands in December 2027, and fines reach €15 million or 2.5% of worldwide annual turnover, whichever is higher.
  1. The CRA enters into force

    Regulation (EU) 2024/2847 is published and the transition clock starts for every product with digital elements sold in the EU.

  2. Conformity assessment bodies

    Rules for notifying conformity assessment bodies apply, so Notified Bodies can be designated ahead of the main obligations.

  3. in force now

    Reporting obligations apply

    Manufacturers must report actively exploited vulnerabilities and severe incidents through the single reporting platform: an early warning within 24 hours, a notification within 72 hours, then a final report. This covers products already on the market.

  4. Main obligations apply

    Essential cybersecurity requirements, vulnerability handling, technical documentation, SBOMs, conformity assessment and CE marking all become mandatory for products placed on the EU market.

Questions we hear first

We don't make the firmware. Does the CRA still apply to us?

Usually, yes. If you place a product with digital elements on the EU market under your own name or trademark, the CRA treats you as the manufacturer, even if an ODM designed and built it. Importers and distributors have their own obligations too. Your CRA consultant or legal counsel should confirm your role for each product line.

Does VexRoute file the report to ENISA for us?

No. You stay the manufacturer and you submit the report. VexRoute starts the CRA clock when the factory's answer arrives and gives you a pre-filled packet for the 24-hour early warning and the 72-hour notification, with the affected SKUs, firmware versions and the factory's mitigation details already in place. You review it, adjust it and submit it.

Does the factory have to share its customer list or source code?

No. The factory only answers questions about firmware families it already supplies. Brands link themselves to the families they buy. No source code is required, and customers never see each other.

How is VexRoute priced?

By the number of firmware families you track and the supplier connections you need, never per incident. A bad week of CVEs shouldn't cost you more.

Read all questions

Be ready before the next advisory lands.

Map your SKUs, connect your factories and have a working CRA response channel in place. Talk to us about your range and we'll show you VexRoute on your own products.

Or write to menachem@vexroute.com.