CVE-2026-93289 PUBLISHED

OS command injection in Eufy Omni C20, Omni X10 Pro

Assigner: icscert
Reserved: 17.09.2026 Published: 24.09.2026 Updated: 24.09.2026

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9

Product Status

Vendor Eufy
Product Omni C20
Versions Default: unaffected
  • affected from 0 to 1.6.4 (excl.)
Vendor Eufy
Product Omni X10 Pro
Versions Default: unaffected
  • affected from 0 to 1.6.4 (excl.)

Solutions

Eufy recommends users to upgrade to version 1.6.4 or later.

Credits

  • Jared of Somerset Recon reported these vulnerabilities to CISA. finder

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE