{"schema_version":1,"title":"Eufy Omni C20 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 3 vulnerabilities in Eufy Omni C20: 3 in the last 7 days and 3 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-93291, was published on 24 September 2026.","url":"https://junglewise.ai/threats/technologies/omni-c20","json_url":"https://junglewise.ai/threats/technologies/omni-c20.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/omni-c20","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":3,"critical":1,"exploited":0,"last_7_days":3,"last_30_days":3,"last_90_days":3,"last_365_days":3},"latest":[{"cve":"CVE-2026-93291","cvss":9.4,"epss":0.0024,"slug":"cve-2026-93291-omni-c20-lacks-proper-certificate-validation-which-could-allow-an","title":"Eufy Omni C20 improper certificate validation in SSL/TLS","severity":"critical","exploited":false,"published_at":"2026-09-24T20:17:34.463+00:00","url":"https://junglewise.ai/threats/cve-2026-93291-omni-c20-lacks-proper-certificate-validation-which-could-allow-an"},{"cve":"CVE-2026-93290","cvss":5.5,"epss":0.0011,"slug":"cve-2026-93290-omni-c20-uses-hard-coded-credentials-that-could-allow-an-attacker","title":"Eufy Omni C20 hard-coded credentials in log files","severity":"medium","exploited":false,"published_at":"2026-09-24T20:17:34.307+00:00","url":"https://junglewise.ai/threats/cve-2026-93290-omni-c20-uses-hard-coded-credentials-that-could-allow-an-attacker"},{"cve":"CVE-2026-93289","cvss":7.5,"epss":0.0068,"slug":"cve-2026-93289-eufy-omni-c20-and-x10-pro-os-command-injection-and-certificate","title":"The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands dur","severity":"high","exploited":false,"published_at":"2026-09-24T20:17:34.137+00:00","url":"https://junglewise.ai/threats/cve-2026-93289-eufy-omni-c20-and-x10-pro-os-command-injection-and-certificate"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Eufy Omni C20","slug":"omni-c20","vendor":{"name":"Eufy","slug":"eufy","url":"https://junglewise.ai/threats/vendors/eufy"},"aliases":[],"category":"security-camera","description":"Smart wireless security camera with built-in video recording and cloud storage capabilities.","url":"https://junglewise.ai/threats/technologies/omni-c20"},"most_severe":[{"cve":"CVE-2026-93291","cvss":9.4,"epss":0.0024,"slug":"cve-2026-93291-omni-c20-lacks-proper-certificate-validation-which-could-allow-an","title":"Eufy Omni C20 improper certificate validation in SSL/TLS","severity":"critical","exploited":false,"published_at":"2026-09-24T20:17:34.463+00:00","url":"https://junglewise.ai/threats/cve-2026-93291-omni-c20-lacks-proper-certificate-validation-which-could-allow-an"},{"cve":"CVE-2026-93289","cvss":7.5,"epss":0.0068,"slug":"cve-2026-93289-eufy-omni-c20-and-x10-pro-os-command-injection-and-certificate","title":"The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands dur","severity":"high","exploited":false,"published_at":"2026-09-24T20:17:34.137+00:00","url":"https://junglewise.ai/threats/cve-2026-93289-eufy-omni-c20-and-x10-pro-os-command-injection-and-certificate"},{"cve":"CVE-2026-93290","cvss":5.5,"epss":0.0011,"slug":"cve-2026-93290-omni-c20-uses-hard-coded-credentials-that-could-allow-an-attacker","title":"Eufy Omni C20 hard-coded credentials in log files","severity":"medium","exploited":false,"published_at":"2026-09-24T20:17:34.307+00:00","url":"https://junglewise.ai/threats/cve-2026-93290-omni-c20-uses-hard-coded-credentials-that-could-allow-an-attacker"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}