VYPR
advisoryPublished Sep 24, 2026· 1 source

CISA Warns of Critical Vulnerabilities in Eufy Smart Home Devices

CISA has issued an advisory detailing three critical vulnerabilities in Eufy Omni C20 and Omni X10 Pro smart home devices, potentially allowing attackers to inject commands, access sensitive data, and perform man-in-the-middle attacks.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory highlighting significant security flaws affecting Eufy's Omni C20 and Omni X10 Pro smart home devices. These vulnerabilities, if exploited, could grant attackers unauthorized access and control over the affected devices, posing a risk to user privacy and data security.

Three distinct vulnerabilities have been identified. The first, CVE-2026-93289, is an OS command injection flaw that can be exploited during the device pairing process. An unauthenticated attacker could leverage this vulnerability to execute system-level commands, potentially leading to a full compromise of the device. This vulnerability affects both the Omni C20 and Omni X10 Pro models.

Adding to the security concerns, CVE-2026-93290 involves the use of hard-coded credentials within the Omni C20 device. This weakness could allow an attacker to monitor log files and potentially extract credentials, which might then be used to gain access to sensitive information such as mapping data. This specific vulnerability is noted for the Omni C20 model.

The most critical flaw, CVE-2026-93291, is a certificate validation issue present in the Omni C20. This vulnerability enables attackers to perform man-in-the-middle (MITM) attacks. By intercepting and potentially manipulating communication between the device and its servers, an attacker could execute arbitrary code, leading to a severe compromise of the device and its connected network.

All three vulnerabilities affect versions prior to 1.6.4 for the Eufy Omni C20. For the Omni X10 Pro, CVE-2026-93289 is also present in versions prior to 1.6.4. The severity of these issues is underscored by their CVSS scores, with CVE-2026-93291 rated as Critical (9.4) and CVE-2026-93289 also rated as High (7.5) and Critical (9.0) depending on the CVSS version used.

Eufy, the vendor, recommends that users upgrade their devices to version 1.6.4 or later to mitigate these risks. While no known public exploitation has been reported to CISA at this time, the potential impact of these vulnerabilities necessitates prompt action from users. CISA advises minimizing network exposure for all control system devices and ensuring they are not accessible from the internet, recommending the use of secure methods like VPNs for remote access.

These findings were reported to CISA by Jared of Somerset Recon. The advisory serves as a critical alert for users of Eufy smart home devices, emphasizing the ongoing need for vigilance and timely patching of IoT and smart home technology to prevent potential security breaches.

Synthesized by Vypr AI