CVE-2026-93291
9.4Eufy · Omni C20
The Eufy Omni C20 fails to perform proper certificate validation, enabling man-in-the-middle attacks that allow unauthenticated attackers to execute arbitrary code.
Executive summary
A critical vulnerability in Eufy Omni C20 firmware allows unauthenticated remote attackers to execute arbitrary code via man-in-the-middle attacks.
Vulnerability
This flaw is classified as an improper certificate validation vulnerability (CWE-295), which allows an unauthenticated attacker to intercept and manipulate network traffic to achieve remote code execution.
Business impact
The potential for unauthenticated remote code execution presents a severe risk to organizational security, as it grants attackers full control over the affected device. Given the CVSS score of 9.4, this vulnerability is critical and could facilitate lateral movement into the broader network or the exfiltration of sensitive data handled by the device.
Remediation
Immediate Action: Update the Eufy Omni C20 firmware to version 1.6.4 or later as recommended by the vendor.
Proactive Monitoring: Review device access logs for unusual traffic patterns and monitor network traffic for signs of unauthorized interception or man-in-the-middle activity.
Compensating Controls: Isolate affected devices on a restricted network segment and employ network-level traffic inspection to detect anomalies in encrypted communication channels.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a significant risk due to the ease of exploitation and the high impact of remote code execution. Administrators must prioritize the deployment of firmware version 1.6.4 across all deployed Eufy Omni C20 units immediately to eliminate the underlying certificate validation flaw.
More Eufy CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by Jared of Somerset Recon reported these vulnerabilities to CISA., per the CVE Program record.