One answer from the factory. Every brand covered.
VexRoute is the vulnerability channel between ODM factories in China and the EU brands they supply. When a CVE hits a shared chipset or SDK, the factory answers once and every affected brand gets that answer, mapped to its own SKUs, with the CRA clock already running.
CRA reporting obligations have applied since 11 September 2026, including to products already on the market.
Your products are built in Shenzhen. Your reporting deadline is set in Brussels.
Most connected electronics sold by European brands, from smart cameras and kids' watches to pet trackers, TV boxes and 5G routers, run firmware written by an ODM in Guangdong. Often it sits on a shared platform or chipset SDK that dozens of other brands also use.
So when a vulnerability lands in that chipset, every brand asks the same factory the same question at the same time: are we affected, which SKUs and firmware, and is there a fix?
The questions arrive in a generic sales inbox, in different languages and formats, six or seven hours out of sync. Nobody on either side owns the answer. It takes days. The CRA gives you 24 hours.
sales@factory-example.cn
23 unread
Brand in Amsterdam
09:12 CET
Are our cameras affected by the new Wi-Fi chipset CVE? Legal needs an answer today.
Brand in Lyon
09:40 CET
Please fill in the attached spreadsheet for every SKU you supply to us.
Importer in Munich
10:05 CET
Which firmware versions are we running? Is there a patch date?
Brand in Madrid
11:30 CET
Re: Re: Fwd: urgent security question, see thread below
Brand in Warsaw
13:15 CET
Our CRA consultant says we must report within 24 hours. Please confirm status.
Brand in Milan
16:50 CET
Following up again. Is anyone on your side handling this?
同一个问题,二十三种格式。工厂在深圳时间晚上才看到。The same question in twenty-three formats. The factory sees it in the Shenzhen evening.
How VexRoute works
Step 1: Map your products
Link each SKU to the firmware family it runs and the ODM behind it. Shared firmware becomes visible across your whole catalogue.Step 2: Connect your factories
Each ODM gets a bilingual Chinese and English workspace. They see the firmware families their customers rely on, nothing more.Step 3: Ask once, answer once
When a CVE lands, one structured question goes to the factory. They answer per firmware family: not affected, affected, fixed or under investigation.Step 4: Route and report
Every linked brand receives the answer against its own SKUs, with the CRA clock started and an ENISA reporting packet pre-filled for review.
When a CVE drops, have the answer before the clock runs out.
Without a channel
With VexRoute
Without a channel
Twenty brands email a sales inbox in different formats and time zones.
- 0 hChipset CVE is published
- 15 hSales forwards it to R&D
- 38 h“Still checking, which SKUs?”
- 54 hBrand resends its product list
- Answer arrives day 6 or later
With VexRoute
One bilingual question to the factory. One answer, routed to every brand.
- 0 hChipset CVE is published
- 8 hODM answers once, per firmware family
- 19 hEarly-warning packet ready to review
- 52 h72-hour notification drafted with the fix
Deadlines: early warning at 24 hours, notification at 72 hours.
Between incidents, the evidence keeps building.
| SKU | Firmware family | Supplier | VEX status | Latest answer |
|---|---|---|---|---|
| CAM-210Indoor camera | IPC-T31 v4.2 | ODM A, Shenzhen | Fixed | Firmware 4.2.7 shipped |
| CAM-220Doorbell camera | IPC-T31 v4.2 | ODM A, Shenzhen | Fixed | Same family, same answer |
| SEN-04Door sensor | ZB-Lite 2.x | ODM B, Dongguan | Not affected | Chipset not used |
| PLG-11Smart plug | WB3S-Plug 1.9 | ODM C, Zhongshan | Under investigation | Answer due in 6 h |
| HUB-01Home hub | Linux-GW 5.1 | ODM A, Shenzhen | Affected | Mitigation published |
Ready when someone asks
- Retailer and marketplace security questionnaires
- Public and enterprise tender requirements
- Internal audits and market surveillance requests
- Notified Body and conformity assessment evidence
- Supplier changes, firmware updates and end-of-support dates
Built for both ends of the route, and the people advising them.
EU brands and importers
You sell it under your name, so the CRA treats you as the manufacturer.
Product, compliance and purchasing teams get one place to ask the factory, see which SKUs are affected and pull a reporting packet in hours, not weeks.
ODMs and OEMs in China
Answer once. Stop filling in fifty spreadsheets.
A bilingual workspace for your R&D and sales teams. Answer per firmware family and every linked EU customer gets the answer, mapped to their own products.
CRA consultants and sourcing agents
You own the advice. We run the pipe underneath it.
Give your clients a working ODM channel and an evidence trail that stands up in audits, without becoming their supplier-chasing department.
Why VexRoute
- One answer per firmware family
- Brands that ship the same firmware get the same answer from the same source, at the same time. The factory does the work once.
- Bilingual where it matters
- The factory side works in Chinese and English, so the R&D engineer who knows the answer can give it directly, without a sales relay.
- Evidence, not just alerts
- Answers become a timestamped trail tied to SKUs, firmware, suppliers, VEX statements and SBOMs. That's what auditors and procurement teams ask for.
- Under your consultant, not instead
- CRA consultants keep the advice, process and audit readiness. VexRoute runs the ODM channel and the evidence pipe beneath their work.
- Priced by what you track
- Firmware families and supplier connections, not incidents. A bad week of CVEs never shows up on your invoice.
The CRA, on one line
The CRA enters into force
Regulation (EU) 2024/2847 is published and the transition clock starts for every product with digital elements sold in the EU.
Conformity assessment bodies
Rules for notifying conformity assessment bodies apply, so Notified Bodies can be designated ahead of the main obligations.
in force now
Reporting obligations apply
Manufacturers must report actively exploited vulnerabilities and severe incidents through the single reporting platform: an early warning within 24 hours, a notification within 72 hours, then a final report. This covers products already on the market.
Main obligations apply
Essential cybersecurity requirements, vulnerability handling, technical documentation, SBOMs, conformity assessment and CE marking all become mandatory for products placed on the EU market.
Questions we hear first
We don't make the firmware. Does the CRA still apply to us?
Usually, yes. If you place a product with digital elements on the EU market under your own name or trademark, the CRA treats you as the manufacturer, even if an ODM designed and built it. Importers and distributors have their own obligations too. Your CRA consultant or legal counsel should confirm your role for each product line.
Does VexRoute file the report to ENISA for us?
No. You stay the manufacturer and you submit the report. VexRoute starts the CRA clock when the factory's answer arrives and gives you a pre-filled packet for the 24-hour early warning and the 72-hour notification, with the affected SKUs, firmware versions and the factory's mitigation details already in place. You review it, adjust it and submit it.
Does the factory have to share its customer list or source code?
No. The factory only answers questions about firmware families it already supplies. Brands link themselves to the families they buy. No source code is required, and customers never see each other.
How is VexRoute priced?
By the number of firmware families you track and the supplier connections you need, never per incident. A bad week of CVEs shouldn't cost you more.
Be ready before the next advisory lands.
Map your SKUs, connect your factories and have a working CRA response channel in place. Talk to us about your range and we'll show you VexRoute on your own products.
Or write to menachem@vexroute.com.

