Skip to content
CISA Alerts on Eufy Omni C20 and X10 Pro Vulnerabilities

CISA Alerts on Eufy Omni C20 and X10 Pro Vulnerabilities

First seen 30 Sep 2026, 06:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 06:56 UTC
  • •Eufy Omni C20 and X10 Pro vacuums are vulnerable to command injection and credential issues.
  • •CISA recommends upgrading to firmware version 1.6.4 or later to mitigate risks.
  • •No known public exploitation of these vulnerabilities has been reported.

CISA issued an advisory on September 24, 2026, regarding vulnerabilities in Eufy Omni C20 and X10 Pro robot vacuums, affecting firmware versions prior to 1.6.4. The vulnerabilities include command injection, hard-coded credentials, and improper certificate validation, allowing attackers to execute system commands and intercept communications. The affected CVEs are CVE-2026-93289, CVE-2026-93290, and CVE-2026-93291, all published on the same date. Eufy recommends users upgrade to version 1.6.4 or later to mitigate these risks. No public exploitation has been reported, but the vulnerabilities pose significant security risks. Users are advised to check their firmware versions and update accordingly. The advisory emphasizes the importance of minimizing network exposure for control systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-24
CISA advisory published
CISA disclosed vulnerabilities in Eufy Omni C20 and X10 Pro, affecting firmware versions before 1.6.4.
CISA
2026-09-24
CVE-2026-93291 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-24
CVE-2026-93289 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-24
CVE-2026-93290 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-29
Vacuum Wars article published
Vacuum Wars reported on the CISA advisory, detailing the vulnerabilities and recommended actions for users.
Vacuumwars
2026-09-30
CISA advisory reminder
CISA reiterated the importance of updating affected Eufy vacuum firmware to version 1.6.4 or later.
CISA

More articles in this cluster (2)

Following this threat?

Track Eufy and CVE-2026-93289 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed