Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-93291: Eufy Omni C20 may let attackers intercept data

CVE-2026-93291 · published 15 days ago
Summary

The Eufy Omni C20 camera does not properly verify the digital proof that its connection is genuine. Because of this, a malicious person could pretend to be the legitimate server, watch or change the information exchanged, and could even run unwanted code on the camera. Install any firmware updates as soon as they are available and keep the device on a secure, trusted network.

What to do
  • Update eufy omni c20 to version 1.6.4 or later.
Affected software
VendorProductAffected versions
eufy omni c20 < 1.6.4
Original advisory text
Improper certificate validation in Eufy Omni C20
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-295Improper Certificate Validation
Timeline
Published24 Sep 2026
Updated7 Oct 2026
First seen24 Sep 2026
Sources
CVE-2026-93291 · MITRE
Track software like this
Free during beta