Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.0

CVE-2026-93289: Eufy Omni C20/X10 Pro can run commands when paired

CVE-2026-93289 · published 15 days ago
Summary

The Omni C20 and Omni X10 Pro hubs can be tricked during the pairing process to run commands on their operating system, even without a login. This could let an outsider take control of the hub and any devices connected to it. Apply the latest firmware updates and limit who can pair new devices to the hub.

What to do
  • Update eufy omni c20 to version 1.6.4 or later.
  • Update eufy omni x10 pro to version 1.6.4 or later.
Affected software
VendorProductAffected versions
eufy omni c20 < 1.6.4
eufy omni x10 pro < 1.6.4
Original advisory text
OS command injection in Eufy Omni C20, Omni X10 Pro
The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.0 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-78OS Command Injection
Timeline
Published24 Sep 2026
Updated7 Oct 2026
First seen24 Sep 2026
Sources
CVE-2026-93289 · MITRE
Track software like this
Free during beta