Severity: CriticalAction: Patch
Eufy Omni C20, Omni X10 Pro
Patch
Apply the vendor's security update for the affected products.
No official fix confirmed yet
Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Developments from the last 30 days, newest first.
CVE-2026-93291 scored CVSS 9.3
Basis: NIST National Vulnerability Database
Eufy Omni C20, Omni X10 Pro
Basis: CISA Cybersecurity Advisories (government advisory)
Apply the vendor's security update for the affected products.