VORANT. Threat Intelligence Sign in Create a free account

Eufy Omni robot vacuums patch RCE flaws

routine vulnerability technology

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Eufy Omni C20 and Omni X10 Pro robot vacuums below v1.6.4 carry command injection, hard-coded credential, and certificate validation flaws enabling remote code execution.

CISA published an ICS advisory detailing three vulnerabilities in Eufy's Omni C20 and Omni X10 Pro robot vacuum/cleaning devices, all fixed in firmware version 1.6.4. The most severe, CVE-2026-93289, is an unauthenticated command injection flaw (CWE-78) affecting both models that allows an attacker to execute system-level commands during the device pairing process. The Omni C20 alone is additionally affected by CVE-2026-93290, use of hard-coded credentials (CWE-798) that could let an attacker who can access log files obtain credentials granting access to sensitive data such as mapping information, and CVE-2026-93291, improper certificate validation (CWE-295) that could enable a man-in-the-middle attacker to execute arbitrary code.

The affected products are consumer/IoT devices manufactured by Eufy (headquartered in China) and deployed worldwide, falling under the Information Technology critical infrastructure sector. CISA states no known public exploitation of these vulnerabilities has been reported at this time. The vulnerabilities were responsibly disclosed to CISA by a researcher identified as Jared of Somerset Recon.

Remediation is straightforward: Eufy recommends all users upgrade affected Omni C20 and Omni X10 Pro devices to firmware version 1.6.4 or later. CISA additionally recommends standard network hygiene for control system devices — minimizing internet exposure, isolating device networks behind firewalls, and using VPNs for any required remote access, while noting VPNs themselves require ongoing patching and are only as secure as connected endpoints.

Mentioned in this report

Vulnerabilities CVE-2026-93289CVE-2026-93290CVE-2026-93291

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-02

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 9,801 reports from 154 sources, 1,536 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs