CVE-2026-93291 PUBLISHED

Improper certificate validation in Eufy Omni C20

Assigner: icscert
Reserved: 17.09.2026 Published: 24.09.2026 Updated: 24.09.2026

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Eufy
Product Omni C20
Versions Default: unaffected
  • affected from 0 to 1.6.4 (excl.)

Solutions

Eufy recommends users to upgrade to version 1.6.4 or later.

Credits

  • Jared of Somerset Recon reported these vulnerabilities to CISA. finder

References

Problem Types

  • CWE-295 Improper certificate validation CWE