{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/eufy/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Omni C20 (\u003c 1.6.4)","Omni X10 Pro (\u003c 1.6.4)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Eufy"],"content_html":"\u003cp\u003eEufy Omni C20 and Omni X10 Pro smart home devices contain multiple critical vulnerabilities that expose them to remote exploitation. These flaws include CVE-2026-93289, an OS command injection vulnerability during the device pairing process; CVE-2026-93290, which involves the use of hard-coded credentials that can be retrieved via log files; and CVE-2026-93291, a flaw involving improper certificate validation.\u003c/p\u003e\n\u003cp\u003eThese vulnerabilities collectively enable an unauthenticated, network-adjacent attacker to execute system-level commands, steal sensitive mapping data, or conduct man-in-the-middle attacks to achieve arbitrary code execution. Given that these devices are deployed globally in both home and IT environments, the potential impact includes unauthorized control over home automation hardware and potential pivot points into connected networks. Eufy has released firmware version 1.6.4 to address these security issues.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of these vulnerabilities can lead to full device compromise, allowing an attacker to execute arbitrary system-level commands, monitor sensitive user data such as home mapping logs, and perform man-in-the-middle interceptions. These devices are used globally, and if left unpatched, they pose a significant risk to the integrity and confidentiality of the home or office network segment where they reside.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Eufy Omni C20 and Omni X10 Pro firmware to version 1.6.4 or later immediately.\u003c/li\u003e\n\u003cli\u003eIsolate IoT devices on a dedicated, firewalled network segment separate from critical IT or business resources.\u003c/li\u003e\n\u003cli\u003eDisable or restrict remote management and internet access for these devices unless explicitly required for operation.\u003c/li\u003e\n\u003cli\u003eImplement VPN-only access for any necessary remote management tasks to reduce the attack surface.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T16:14:35Z","date_published":"2026-09-24T16:14:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-eufy-omni-vulnerabilities/","summary":"Multiple vulnerabilities in Eufy Omni C20 and X10 Pro devices, including command injection, hard-coded credentials, and improper certificate validation, allow unauthenticated attackers to achieve remote code execution and credential theft.","title":"Critical Vulnerabilities in Eufy Omni C20 and X10 Pro","url":"https://feed.craftedsignal.io/briefs/2026-09-eufy-omni-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Eufy","version":"https://jsonfeed.org/version/1.1"}