Executive brief
Eufy's Omni C20 and Omni X10 Pro are home/office security camera systems that manage surveillance, mapping data, and device connectivity. These products contain multiple critical vulnerabilities allowing attackers to execute arbitrary system commands, bypass certificate validation for man-in-the-middle attacks, and access sensitive credentials. An attacker could gain full control of the device, intercept communications, or access stored mapping data without authentication.
Technical details
The advisory covers three distinct vulnerabilities: CVE-2026-93289 is an OS command injection flaw (CWE-78) exploitable during the device pairing process that allows unauthenticated command execution with CVSS 3.1 base score 7.5 and CVSS 4.0 score 9.0. CVE-2026-93290 involves hard-coded credentials (CWE-798) in Omni C20 that permit local authenticated attackers to extract credentials and access mapping data. CVE-2026-93291 reflects improper certificate validation (CWE-295) enabling network-based man-in-the-middle attacks to execute arbitrary code (CVSS 3.1: 9.4, CVSS 4.0: 9.3). All vulnerabilities affect Omni C20 versions prior to 1.6.4; CVE-2026-93289 also affects Omni X10 Pro. The primary attack vectors are adjacent network for command injection, local access for credential abuse, and network-based for certificate validation bypass. Eufy recommends upgrading to version 1.6.4 or later; no active exploitation has been reported.
Affected products
- Eufy Omni C20 <1.6.4
- Eufy Omni X10 Pro <1.6.4
CVE identifiers
- CVE-2026-93289
- CVE-2026-93290
- CVE-2026-93291
Timeline
- 2026-09-24: disclosed: CISA advisory ICSA-26-267-02 published