Contact LitePoint Sales

Please provide your details below and LitePoint will be in touch within two business days.

Product Finder

Search products by wireless technology or standard you’re testing.

Supported Chipsets

Ready to test with more than 350 connectivity and cellular chipsets.

Learn About Testing 5G

IQgig-5G mmWave Test Solution Accelerates Economies of Scale in Manufacturing.

Register for our Next Webinar

LitePoint presents a series of webinars packed with the information you need for the complexities of testing the newest wireless technologies.

Worldwide Support

Software downloads & technical, or hardware support when you need it.

Partner Portal

Get access to partner programs, insights, & expert information.

Innovators Wanted

Experts in Wireless, Driven to Revolutionize. View Open Positions.

Contact Us

Give us a call or send us a message, our sales team is here to help.

Product Security

LitePoint is committed to delivering secure, reliable products that help customers operate with confidence. Security is embedded throughout our product lifecycle, from secure design and development to continuous vulnerability assessment and mitigation. Guided by industry-recognized frameworks and rigorous governance, our Product Security Program helps safeguard data, protect critical operations, and address emerging cybersecurity risks. By integrating security, privacy, and responsible technology practices into everything we build, we support the trust our customers place in LitePoint every day.

Report a security vulnerability

LitePoint test systems sit on the production lines of the world’s wireless device manufacturers. If you have found a security vulnerability in one of our test systems, or in IQfact+, we want to hear from you. This page explains what to report, how to report it, and what happens next.

Submit a vulnerability report

Secure intake form. No account required.

How to report
Our secure online intake form, the single channel for vulnerability reports.
Acknowledgement
Automated confirmation with a Tracking ID immediately on submission.
Who handles it
A named contact from the LitePoint product security team.
Cost to you
Reporting is free. We do not operate a paid bug bounty programme.

Our commitment to you

LitePoint is a Teradyne company, and vulnerability reports are handled by the Teradyne Product Security Incident Response Team (PSIRT) together with the LitePoint engineering organisation, under a single Coordinated Vulnerability Disclosure (CVD) process. When you report a vulnerability to us in good faith, we commit to the following.

We will respond

Every report receives an automated acknowledgement with a Tracking ID. A member of our Product Security team then reviews it and follows up with you directly.

We will keep you informed

Once we have assessed your report, we will tell you whether we have reproduced the issue, how we have rated it, and what we intend to do about it.

We will not pursue you

If you follow the rules of engagement below, we will treat your research as authorised and will not initiate legal action or a law enforcement referral against you. See Safe harbour.

We will credit you

Where you would like it, and where a public advisory is issued, we are glad to credit you by name or handle. You may also ask to remain anonymous.

What is in scope

Security vulnerabilities in LitePoint test systems and the software that runs on and alongside them. Examples include:

  • Connectivity and mmWave test systems: IQxel (including IQxel-MW and IQxel-M4W) and IQgig (including IQgig-5G, IQgig-IF and IQgig-RF).
  • Cellular test systems: IQxstream (including IQxstream-5G), IQcell (including IQcell-5G) and IQfr (including IQfr1-RU).
  • IQfact+ and our test software: test executives, calibration and measurement software, drivers, APIs and automation interfaces.
  • System controllers and instrument firmware: the system PC and the Windows image as we ship and configure it, instrument firmware and bootloaders, onboard services, and debug or service interfaces.
  • Remote control and integration interfaces: SCPI and other instrument control protocols, network services, remote access features, and the interfaces used to integrate a tester into a production line or handler.
  • LitePoint operated internet facing services: our websites, customer and support portals, and software download, licensing and update infrastructure.
  • Update and supply chain integrity: software and firmware update mechanisms, signing and verification, licensing enforcement, and any way to get unauthorised code onto a tester.

These are examples, not a complete list. Our portfolio changes over time, so if your finding affects a LitePoint product that is not named here, please submit it anyway and name the product in the form. We will route it to the right team.

What is out of scope

The following are generally not accepted. We may still review a report in this list if you can demonstrate concrete security impact, so if you are in doubt, submit it and tell us why it matters.

  • Raw output from an automated scanner with no demonstrated exploitability or impact.
  • Missing HTTP security headers, cookie flags, TLS configuration preferences, or SPF/DKIM/DMARC findings with no demonstrated impact.
  • Behaviour that is documented and intended, or that requires a setting the operator has deliberately enabled, unless you can show it is exploitable in a default or reasonably expected configuration.
  • The fact that an instrument control protocol such as SCPI is unauthenticated by design on a segmented test network, absent a demonstrated way to reach it from somewhere it should not be reachable.
  • Attacks that require the attacker to already have physical possession of a tester they are free to dismantle, with no path to remote or in-line exploitation.
  • Denial of service, volumetric, load or stress testing of any kind.
  • Social engineering, phishing, or physical intrusion against employees, customers, offices or facilities.
  • Vulnerabilities in third party operating systems, handlers, instruments, MES systems or services we do not control. Report those to the relevant vendor, and tell us if a LitePoint product is affected as a result.
  • Products and software releases that have reached end of support, unless the issue also affects a supported release.
  • Reports that consist only of a version number matched against a public CVE list, with no analysis of whether the affected code path is reachable in our product.

Rules of engagement

Our systems are high value production test equipment that transmits and receives RF, and they are often the single point of test on a manufacturing line. Please observe the following.

Never test against a tester in productive use. Do not test on any system that is running a live production or qualification workload. Taking a tester down or corrupting its calibration can halt a customer’s manufacturing line and invalidate results already produced.

Do not transmit RF outside a shielded enclosure or a properly licensed test environment. Do not attempt to make a system emit outside its intended configuration, power levels or frequency allocations. Unlicensed emissions can breach radio regulations in your jurisdiction and interfere with licensed services.

  • Test only on equipment you own, or for which you have the documented, explicit permission of the owner. Never test on a LitePoint customer’s equipment.
  • Keep test systems on an isolated network segment, separate from any production or corporate network.
  • Stay within scope. Do not pivot to other systems, networks or accounts.
  • Use only the minimum access needed to demonstrate the issue. Stop as soon as you have proven it, and do not attempt to escalate further.
  • Do not access, copy, modify or destroy data that is not yours. Test results, calibration data and test plans can reveal a customer’s unreleased product designs, so if you encounter data of this kind, or personal data or credentials, stop immediately, do not retain a copy, and tell us in your report.
  • Do not degrade, interrupt or damage any service, system or piece of equipment, and do not alter calibration data on a system you do not own.
  • Report the issue to us promptly after discovery, and give us a reasonable opportunity to remediate before disclosing it publicly.
  • Keep the details confidential between you and us until we have jointly agreed that it is appropriate to publish.
  • Do not use your findings, or the fact of your access, to demand payment. Reports submitted with a payment demand attached are handled as extortion, not research.

Safe harbour

If you make a good faith effort to comply with this policy during your research, we will consider your activity authorised. We will not initiate or support legal action against you, or refer you to law enforcement, in connection with research conducted in accordance with this policy. If a third party brings legal action against you for research that complied with this policy, we will make that compliance known.

This policy does not give you permission to act on any network or system belonging to a third party, including our customers and suppliers, and it does not waive any obligation you have under applicable law, including radio and telecommunications regulations. If you are unsure whether something you plan to do is permitted, ask us first through the form before you do it.

What to include in your report

The intake form walks you through six short sections. The more precise you are, the faster we can reproduce the issue and route it to the engineers who own the affected code. Please have the following ready.

1. About you

Your name or handle, and an email address we can reply to. An organisation name is optional, and so is a PGP public key if you would like our follow-up encrypted.

2. Affected product

The tester model or software affected, the exact firmware, IQfact+ or software version and build, the system controller OS version, and the interface, port or URL where you found the issue. This determines which engineering team receives your report.

3. The vulnerability

The vulnerability class, a CVE identifier if one already exists, and a technical description of the flaw: the vulnerable component, the root cause, and the conditions under which it triggers.

4. Proof and reproduction

Numbered, self-contained steps that let an engineer reproduce the issue on a clean system, plus any proof of concept request, payload, script or instrument command sequence involved.

5. Impact

What an attacker gains, and be explicit if it includes falsifying test results, altering calibration, or reaching customer test data. Also what they need first: network position, a valid account, administrative rights, physical access.

6. Exposure and disclosure

Whether you have seen the issue being exploited, whether any part of it is already public, any disclosure deadline you are working to, and anything else we should know.

Attachments

You can attach supporting evidence: screenshots, logs, packet captures, crash dumps, or proof of concept code. The form accepts .txt, .py, .js, .html, .pdf, .png, .jpg, .jpeg, .gif, .pcap, .cap, .zip, .tar and .gz files. Every attachment is scanned for malware on arrival. Please redact any third party personal data before you upload, and never include live customer data, test results or calibration data belonging to a customer.

What happens after you submit

  1. You get a Tracking ID

    As soon as your report is received you get an automated confirmation email with a Tracking ID. Quote it in any follow-up so we can find your report instantly.

  2. We triage and route it

    Your report is assessed for severity and regulatory significance, then routed to the LitePoint product security and engineering team, where a named contact picks it up.

  3. We validate and rate it

    Our engineers attempt to reproduce the issue and assign a severity using CVSS. We will come back to you if we need more detail, and we will tell you the outcome of the assessment, including if we conclude it is not a vulnerability, and why.

  4. We remediate

    Confirmed issues are tracked to a fix in our engineering systems. Timelines depend on severity and on the release and qualification cycle of the affected product, and a fix for production test equipment must be validated before it ships. We will keep you updated on progress.

  5. We disclose together

    Where appropriate we publish an advisory and, if applicable, request a CVE identifier. We coordinate timing with you and credit you as you prefer. If we are required to notify a regulator or a national CSIRT, we will do so and let you know.

If this is not a product vulnerability

Please use the right channel so your issue reaches the right people. This process is only for suspected security vulnerabilities.

  • A non-security product fault, a measurement question, or you need help with a product: contact LitePoint support through your usual support channel.
  • A commercial, sales or general enquiry: use the contact options elsewhere on this website.
  • You believe one of your own LitePoint systems has been compromised: disconnect it from the network, stop using it for production test, and contact your LitePoint support representative immediately, telling them you believe it is a security incident.
  • A phishing email, or a website impersonating LitePoint: report it through the form and select information disclosure or security misconfiguration. Do not interact with the message further.

LitePoint is a Teradyne company. If your finding affects another Teradyne brand, whether Universal Robots, Mobile Industrial Robots, or Teradyne test systems, you can submit it through the same form and it will be routed to the right team.

Ready to report?

The form takes about ten minutes if you have your reproduction steps and evidence to hand. It is submitted over an encrypted connection directly to our Product Security team.

By submitting a report you confirm that you have read and will follow this policy, and you agree that we may use the information you provide to investigate and remediate the issue, and to notify affected customers, partners and regulators as required. Your report is handled confidentially by our Product Security team.

We do not operate a paid bug bounty programme and do not offer monetary rewards for vulnerability reports.

LitePoint Coordinated Vulnerability Disclosure policy. Effective August 26, 2026. We may update this policy; the version published here at the time you begin your research is the one that applies.