Eufy Omni C20 and X10 Pro Firmware Update Addresses Three Vulnerabilities
Quick Answer
CISA published ICSA-26-267-02 for Eufy Omni C20 and Omni X10 Pro devices below firmware 1.6.4. Identify affected devices, install vendor-supported firmware 1.6.4 or later, validate pairing, mapping, cloud, and control workflows, and retain firmware and change evidence.
Confirm Scope And Apply The Supported Fix
What to do now: Locate Omni C20 and Omni X10 Pro devices, record model and firmware, update affected devices to vendor-supported firmware 1.6.4 or later, reduce unnecessary exposure, validate normal operation, and preserve before-and-after evidence.
Last verified: 2026-09-29 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | Eufy Omni C20 and Omni X10 Pro robot vacuums before firmware 1.6.4 |
|---|---|
| Advisory | ICSA-26-267-02 |
| CVEs | CVE-2026-93289, CVE-2026-93290, CVE-2026-93291 |
| Authoritative release date | 2026-09-24 06:00:00 UTC |
| Authority revision date | 2026-09-24 06:00:00 UTC |
| Affected versions | Eufy Omni C20 and Omni X10 Pro firmware versions earlier than 1.6.4; CVE-2026-93290 and CVE-2026-93291 are listed only for Omni C20. |
| Fixed version | Eufy firmware 1.6.4 or later |
| CVSS base score | 5.5 / 7.5 / 9.4 (official CVSS v3.1) |
| CVSS severity | Medium to Critical |
| Exploitation status | CISA reports no known public exploitation specifically targeting these vulnerabilities; no exploitation claim is inferred. |
What Changed
CISA reports command injection during pairing for both models, hard-coded credentials in Omni C20, and improper certificate validation in Omni C20. Successful exploitation could permit system-command execution, information access, or arbitrary code execution.
What To Validate Now
- Inventory. Locate Eufy Omni C20 and Omni X10 Pro devices; record model, serial or asset identifier, firmware, network segment, internet and remote-access exposure, application or cloud account, owner, and business use.
- Establish applicability. Compare model and firmware with ICSA-26-267-02. Both models are listed for CVE-2026-93289; only Omni C20 is listed for CVE-2026-93290 and CVE-2026-93291. Do not infer another Eufy model is affected.
- Remediate. Use the vendor-supported update path to install firmware 1.6.4 or later. CISA also recommends minimizing network exposure, isolating remote devices from business networks, and using current secure remote-access methods where needed.
- Validate. Confirm firmware 1.6.4 or later, validate pairing, mapping, cleaning, application, cloud, and remote-control workflows, review device and network logs for anomalies, and document exceptions.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Perform impact analysis before deploying defensive measures, preserve device configuration where supported, keep the device powered and connected during the approved update, and do not interpret the critical score as confirmation of exploitation.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.


