The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.
Eufy recommends users to upgrade to version 1.6.4 or later.