CRA vulnerability reporting
A vulnerability-database match starts as a draft finding. It does not by itself prove exploitation, confirm product impact or start a statutory reporting clock. An authorized reviewer selects the exact finding and affected product version, then records applicability, reachability, awareness rationale and evidence.
When the manufacturer confirms a reportable case, Meshanics maintains the progressive case record: awareness time and rationale, required milestones, submission revisions and references, attachments by digest, remediation and closure review. The platform does not submit to ENISA or another authority on the customer's behalf.
The console correlates an affected artifact with devices that currently report that version. This is operational exposure evidence, not hardware attestation. Issued dossiers include the reviewed case and supporting records with a signed byte manifest for independent verification.
See Incident reporting, Product register and support periods, and Evidence and reports.