<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Omni X10 Pro (&lt; 1.6.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/omni-x10-pro--1.6.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 24 Sep 2026 16:14:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/omni-x10-pro--1.6.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities in Eufy Omni C20 and X10 Pro</title><link>https://feed.craftedsignal.io/briefs/2026-09-eufy-omni-vulnerabilities/</link><pubDate>Thu, 24 Sep 2026 16:14:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-eufy-omni-vulnerabilities/</guid><description>Multiple vulnerabilities in Eufy Omni C20 and X10 Pro devices, including command injection, hard-coded credentials, and improper certificate validation, allow unauthenticated attackers to achieve remote code execution and credential theft.</description><content:encoded><![CDATA[<p>Eufy Omni C20 and Omni X10 Pro smart home devices contain multiple critical vulnerabilities that expose them to remote exploitation. These flaws include CVE-2026-93289, an OS command injection vulnerability during the device pairing process; CVE-2026-93290, which involves the use of hard-coded credentials that can be retrieved via log files; and CVE-2026-93291, a flaw involving improper certificate validation.</p>
<p>These vulnerabilities collectively enable an unauthenticated, network-adjacent attacker to execute system-level commands, steal sensitive mapping data, or conduct man-in-the-middle attacks to achieve arbitrary code execution. Given that these devices are deployed globally in both home and IT environments, the potential impact includes unauthorized control over home automation hardware and potential pivot points into connected networks. Eufy has released firmware version 1.6.4 to address these security issues.</p>
<h2 id="impact">Impact</h2>
<p>The successful exploitation of these vulnerabilities can lead to full device compromise, allowing an attacker to execute arbitrary system-level commands, monitor sensitive user data such as home mapping logs, and perform man-in-the-middle interceptions. These devices are used globally, and if left unpatched, they pose a significant risk to the integrity and confidentiality of the home or office network segment where they reside.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Eufy Omni C20 and Omni X10 Pro firmware to version 1.6.4 or later immediately.</li>
<li>Isolate IoT devices on a dedicated, firewalled network segment separate from critical IT or business resources.</li>
<li>Disable or restrict remote management and internet access for these devices unless explicitly required for operation.</li>
<li>Implement VPN-only access for any necessary remote management tasks to reduce the attack surface.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>