www.cisa.gov 24 Sept 2026, 12:00 UTC

CISA Warns of Critical Flaws in Eufy Robot Vacuums

CISA has warned of three vulnerabilities affecting Eufy Omni C20 and Omni X10 Pro robot vacuum cleaners. Versions before 1.6.4 are affected, with the C20 impacted by CVE-2026-93289, CVE-2026-93290 and CVE-2026-93291, while the X10 Pro is affected by CVE-2026-93289. Successful exploitation could enable system-level commands or arbitrary code execution. The advisory gives an overall CVSS v3 score of 9.4.

CVE-2026-93289 is an OS command-injection flaw that could let an unauthenticated attacker execute system commands during the pairing process. CVE-2026-93290 concerns hard-coded credentials in the Omni C20, potentially allowing an attacker to monitor log files and obtain credentials for information such as mapping data. CVE-2026-93291, also affecting the C20, involves inadequate certificate validation and could enable a man-in-the-middle attack leading to arbitrary code execution.

Jared of Somerset Recon reported the issues to CISA. No known public exploitation specifically targeting these vulnerabilities had been reported to CISA as of 24 September 2026.

Eufy recommends upgrading both products to version 1.6.4 or later. CISA also advises reducing network exposure, keeping control-system devices behind firewalls and separating them from business networks; where remote access is necessary, it recommends properly secured and updated VPNs.

View full article

Article by CyberSIXT