Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
xfinity-home
26
In Scope
31
Out of Scope
In-Scope Assets (26)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| *-cvr-aws-*.sys.comcast.net | URL | No | ||
| *.dh-commerce.com | URL | No | ||
| *.ssr.ccp.xcal.tv | URL | No | ||
| *.xfinityhome.com | URL | No | ||
| *.xfiplatform.com | URL | No | ||
| *signalservice.comcast.net | URL | No | ||
| Internet.xfinity.com | URL | No | ||
| Xfinity Android mobile app | ANDROID | No | - | |
| Xfinity Home Hardware (items listed below in brief) | HARDWARE | No | - | |
| Xfinity Home cameras | HARDWARE | No | - | |
| Xfinity iOS mobile app | IOS | No | - | |
| aiq-prod.codebig2.net | URL | No | ||
| csp-pci.prod.codebig2.net | URL | No | ||
| gw.api.dh.comcast.com | URL | No | ||
| https://apps.apple.com/us/app/xfinity/id1178765645 | IOS | No | - | |
| https://csp-prod.codebig2.net | URL | No | ||
| https://home.xfinity.com | URL | No | ||
| https://play.google.com/store/apps/details?id=com.xfinity.digitalhome&hl=en_US&gl=US | ANDROID | No | ||
| orc-xfi.com | URL | No | ||
| siorc.xfinity.com | URL | No | ||
| smartinet.xfinity.com | URL | No | ||
| speedtest.xfinity.com | URL | No | ||
| xFi Gateways (e.g., XB3, XB6, XB7) | HARDWARE | No | - | |
| xFi Pods | HARDWARE | No | - | |
| xhomeapi-*.cloud.comcast.net | URL | No | ||
| xhomeapi-*.codebig2.net | URL | No |
Out-of-Scope Assets (31)
| Asset | Category | Bounty | |
|---|---|---|---|
| *.adnxs.com | URL | No | |
| *.adobedtm.com | URL | No | |
| *.amazon-adsystem.com | URL | No | |
| *.appcenter.ms | URL | No | |
| *.cimcontent.net | URL | No | |
| *.criteo.net | URL | No | |
| *.demdex.net | URL | No | |
| *.fwmrm.net | URL | No | |
| *.hfc.comcastbusiness.net | URL | No | |
| *.hsd1.*.comcast.net | URL | No | |
| *.identity.xfinity.com | URL | No | |
| *.kampyle.com | URL | No | |
| *.openx.net | URL | No | |
| *.pulseinsights.com | URL | No | |
| *.webcontentassessor.com | URL | No | |
| *.wurfulcloud.com | URL | No | |
| *.xerxessecure.com | URL | No | |
| 10.0.0.0/8 | OTHER | No | |
| 172.26.128.0/18 | OTHER | No | |
| 184.112.0.0/13 | OTHER | No | |
| 184.122.0.0/15 | OTHER | No | |
| 3rd Party Devices (known as Works with Xfinity) | HARDWARE | No | |
| 50.128.0.0/12 | OTHER | No | |
| 50.152.0.0/13 | OTHER | No | |
| 96.201.0.0/16 | OTHER | No | |
| 96.202.128.0/17 | OTHER | No | |
| 96.203.0.0/16 | OTHER | No | |
| \*\business.comcast.com | URL | No | |
| admin.selectwifi.xfinity.com | URL | No | |
| https://login.xfinity.com | URL | No | |
| oauth.xfinity.com | URL | No |