TL;DR
On September 24, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published an advisory detailing multiple Eufy robot vacuum vulnerabilities. These critical security flaws expose the Omni C20 and Omni X10 Pro models to OS command injection and Man-in-the-Middle (MitM) attacks. Eufy owners must update their device firmware to version 1.6.4 or later immediately to secure their home networks.
- Product: Eufy Omni C20
- Vulnerabilities: 3 flaws (CVE-2026-93291, CVE-2026-93289, CVE-2026-93290)
- Highest severity: 9.4 (Critical · CVSSv3)
- Worst impact: Improper certificate validation in
- Status: No confirmed exploitation yet; patches available
- Action: Update to 1.6.4 now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-93291 | 9.4 | Improper certificate validation in | 1.6.4 | Not exploited |
| CVE-2026-93289 | 7.5 | OS command injection in , Omni X10 Pro | 1.6.4 | Not exploited |
| CVE-2026-93290 | 5.5 | Use of Hard-coded Credentials in | 1.6.4 | Not exploited |
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy It Matters
Millions of households deploy smart cleaning appliances on their private residential networks. Therefore, Eufy robot vacuum vulnerabilities pose severe privacy and security risks for ordinary consumers. The most dangerous flaw, an improper certificate validation issue, carries a critical CVSS base score of 9.4. Another severe defect permits OS command injection with a CVSS v3 rating of 7.5.
According to the official advisory, “No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time”. Furthermore, researchers have not published any public proof-of-concept exploit code. However, unpatched vacuums remain an easy target for local network intrusion. CISA warned that “Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code”.
How The Attack Works
The flaws span the pairing process, credential management, and secure communications. The command injection defect targets the initial device pairing sequence. The advisory states, “The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process”.
Separately, the Omni C20 model lacks proper TLS certificate validation. A malicious actor on the local network can intercept traffic, perform a Man-in-the-Middle attack, and execute arbitrary code. Finally, the platform uses hard-coded credentials that expose sensitive mapping data through log files.
Affected Versions
These security flaws affect Eufy Omni C20 and Omni X10 Pro firmware versions prior to 1.6.4.
Patch Or Mitigation Steps
Eufy released patched software to address all three vulnerabilities. Administrators should update their vacuum firmware through the official mobile application immediately. Additionally, users should isolate smart home devices on a dedicated guest network to limit exposure.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!