You could read up on
http://en.wikipedia.org/wiki/Responsible_disclosure
Preferrably contact the vendor directly without publishing your findings online. Give them time to fix the issue. If they do not react and you feel there is a great danger if you do not disclose the existence of this vulnerability, publish it.