CVE-2026-93289: OS command injection in Eufy Omni C20, Omni X10 Pro
Published Sep 24, 2026
·Updated
The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.
Affected Software
2 affected components
Eufy Omni C20
Eufy Omni X10 Pro
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Eufy Omni C20, Omni X10 Proto a version that resolves this vulnerability.Fixed in 1.6.4
Event History
Sep 24, 2026
CVE Published
via MITRE·07:24 PM
Data Sourced
via MITRE·07:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an account or user interaction?
No. The vulnerability is rated as requiring no privileges and no user interaction.
2
What access does an attacker need?
The attack vector is adjacent, and exploitation occurs during the pairing process. The rating also indicates high attack complexity.