CVE-2026-93289: Eufy Omni c20

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

Affected products

  • Eufy Omni c20: before 1.6.4 (fixed in 1.6.4)
  • Eufy Omni x10 Pro: before 1.6.4 (fixed in 1.6.4)

Published 2026-09-24. Last modified 2026-09-24.