Eufy Omni C20 and X10 Pro Firmware Update Addresses Three Vulnerabilities

P1 — VALIDATE AND UPDATEMedium to Critical · 5.5 / 7.5 / 9.4 (official CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

CISA published ICSA-26-267-02 for Eufy Omni C20 and Omni X10 Pro devices below firmware 1.6.4. Identify affected devices, install vendor-supported firmware 1.6.4 or later, validate pairing, mapping, cloud, and control workflows, and retain firmware and change evidence.

Confirm Scope And Apply The Supported Fix

What to do now: Locate Omni C20 and Omni X10 Pro devices, record model and firmware, update affected devices to vendor-supported firmware 1.6.4 or later, reduce unnecessary exposure, validate normal operation, and preserve before-and-after evidence.

Open the authoritative advisory

Last verified: 2026-09-29 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeEufy Omni C20 and Omni X10 Pro robot vacuums before firmware 1.6.4
AdvisoryICSA-26-267-02
CVEsCVE-2026-93289, CVE-2026-93290, CVE-2026-93291
Authoritative release date2026-09-24 06:00:00 UTC
Authority revision date2026-09-24 06:00:00 UTC
Affected versionsEufy Omni C20 and Omni X10 Pro firmware versions earlier than 1.6.4; CVE-2026-93290 and CVE-2026-93291 are listed only for Omni C20.
Fixed versionEufy firmware 1.6.4 or later
CVSS base score5.5 / 7.5 / 9.4 (official CVSS v3.1)
CVSS severityMedium to Critical
Exploitation statusCISA reports no known public exploitation specifically targeting these vulnerabilities; no exploitation claim is inferred.

What Changed

CISA reports command injection during pairing for both models, hard-coded credentials in Omni C20, and improper certificate validation in Omni C20. Successful exploitation could permit system-command execution, information access, or arbitrary code execution.

What To Validate Now

  1. Inventory. Locate Eufy Omni C20 and Omni X10 Pro devices; record model, serial or asset identifier, firmware, network segment, internet and remote-access exposure, application or cloud account, owner, and business use.
  2. Establish applicability. Compare model and firmware with ICSA-26-267-02. Both models are listed for CVE-2026-93289; only Omni C20 is listed for CVE-2026-93290 and CVE-2026-93291. Do not infer another Eufy model is affected.
  3. Remediate. Use the vendor-supported update path to install firmware 1.6.4 or later. CISA also recommends minimizing network exposure, isolating remote devices from business networks, and using current secure remote-access methods where needed.
  4. Validate. Confirm firmware 1.6.4 or later, validate pairing, mapping, cleaning, application, cloud, and remote-control workflows, review device and network logs for anomalies, and document exceptions.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Perform impact analysis before deploying defensive measures, preserve device configuration where supported, keep the device powered and connected during the approved update, and do not interpret the critical score as confirmation of exploitation.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.