5.4.9 The testing laboratory shall assess that third-party libraries/components used by the firmware are compliant with respective license requirements (GNU General Public License, BSD license, MIT, Creative Commons, Apache, etc.). 5.4.10 The testing laboratory shall assess that there are no exploitable third-party libraries/components. In the event that vulnerabilities are deemed to be highly exploitable, the developer is required to update the libraries/components to a version without vulnerabilities, or to implement a custom patch/fix to address the vulnerability. The testing laboratory shall re-test the binary code following developer’s remediation procedures. The remediated findings and its remediation steps must be included in the report to CCC. 5.4.11 The testing laboratory shall ensure that the firmware and the companion mobile application does not contain hard-coded critical security parameters. 5.4.12 For each false positive, the testing laboratory must work with the developer to provide sufficient justification on why the finding is a false positive. Malware Scan 5.4.13 Developer shall ensure that the binary files submitted is free from known malware. 5.4.14 The binary files shall be subjected to a commercial malware scanner that exists as a cloud solution for malware analysis. Therefore, the developer shall consent to allowing the binary files to be uploaded to a commercial malware scanner for malware analysis. 5.4.15 In the event that firmware and/or the companion mobile application tests positive for malware, the initial malware scan results shall be confirmed using a different malware scanner. If both malware scanners confirm that the binary file tests positive for malware, CCC reserves the right to take appropriate actions against the developer. Mobile Application Scan 5.4.16 Where a companion mobile app is available to facilitate the usage of the DUT, the companion mobile app shall be subjected to binary analysis. The testing laboratory shall prioritise their analysis of the companion mobile app on the following areas: • • • Hardcoded credentials or critical security parameters; Exposure of sensitive information, for example via insecure storage or insecure communication channels; Potential intrusion to privacy for example whether the app requests for rights/permissions that it is deemed not to require such as to user’s calendar or device’s camera; or where data is sent out CLS Publication #2 | Page 12 of 49

Select target paragraph3