CVE-2026-93291

9.4

Eufy · Omni C20

The Eufy Omni C20 fails to perform proper certificate validation, enabling man-in-the-middle attacks that allow unauthenticated attackers to execute arbitrary code.

Executive summary

A critical vulnerability in Eufy Omni C20 firmware allows unauthenticated remote attackers to execute arbitrary code via man-in-the-middle attacks.

Vulnerability

This flaw is classified as an improper certificate validation vulnerability (CWE-295), which allows an unauthenticated attacker to intercept and manipulate network traffic to achieve remote code execution.

Business impact

The potential for unauthenticated remote code execution presents a severe risk to organizational security, as it grants attackers full control over the affected device. Given the CVSS score of 9.4, this vulnerability is critical and could facilitate lateral movement into the broader network or the exfiltration of sensitive data handled by the device.

Remediation

Immediate Action: Update the Eufy Omni C20 firmware to version 1.6.4 or later as recommended by the vendor.

Proactive Monitoring: Review device access logs for unusual traffic patterns and monitor network traffic for signs of unauthorized interception or man-in-the-middle activity.

Compensating Controls: Isolate affected devices on a restricted network segment and employ network-level traffic inspection to detect anomalies in encrypted communication channels.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a significant risk due to the ease of exploitation and the high impact of remote code execution. Administrators must prioritize the deployment of firmware version 1.6.4 across all deployed Eufy Omni C20 units immediately to eliminate the underlying certificate validation flaw.

More Eufy CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Jared of Somerset Recon reported these vulnerabilities to CISA., per the CVE Program record.