CISA published an advisory on 24 September 2026 covering three vulnerabilities in Eufy Omni C20 and Omni X10 Pro robot vacuums running firmware before version 1.6.4. The flaws are CVE-2026-93291, an improper certificate-validation issue rated 9.4 (critical) on CVSS v3; CVE-2026-93289, an OS command-injection flaw rated 7.5; and CVE-2026-93290, involving hard-coded credentials and rated 5.5. All three are fixed in firmware 1.6.4.
The command-injection vulnerability affects the initial pairing process and could allow an unauthenticated attacker to execute system commands. CISA also says that inadequate TLS certificate validation in the Omni C20 could let an attacker on the local network intercept communications through a man-in-the-middle attack and execute arbitrary code. The hard-coded credentials can expose sensitive mapping data in log files.
CISA stated that no known public exploitation specifically targeting these vulnerabilities had been reported, and the article says no public proof-of-concept code had been published. It nevertheless warned that successful exploitation could allow system-level commands or arbitrary code to run.
Eufy owners should update affected vacuums to firmware 1.6.4 or later through the official mobile application. The article also recommends placing smart-home devices on a dedicated guest network to limit potential exposure.