IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Eufy Omni C20, Omni X10 Pro

CRITICAL
CVSS 9.4
Date 2026-09-24T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code.

// Vulnerabilities (3)

CVE ID CVSS Score Severity Description
CVE-2026-93289 7.5 high
The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.
CVE-2026-93290 5.5 medium
Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.
CVE-2026-93291 9.4 critical
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

// Remediations (1)

Mitigation: Eufy recommends users to upgrade to version 1.6.4 or later.
Eufy recommends users to upgrade to version 1.6.4 or later.

// References