vuln-advisoryregulatorNewsThe Broadside1 min read

CISA flags command injection, hardcoded creds in Eufy Omni C20, X10 Pro

Three CVEs disclosed for a Chinese-manufactured camera line as federal supply-chain scrutiny of networked devices intensifies, no word on patch timeline or government deployment.


TL;DR

CISA published three vulnerabilities in Eufy Omni C20 and Omni X10 Pro devices running firmware below 1.6.4. CVE-2026-93289 is an unauthenticated command injection during pairing affecting both models. CVE-2026-93290 (hardcoded credentials exposing mapping data) and CVE-2026-93291 (certificate validation failure enabling man-in-the-middle arbitrary code execution, CVSS 3.1 score 9.4) affect the Omni C20 only. Eufy recommends upgrading to 1.6.4. CISA reports no known public exploitation. The advisory lands against a backdrop of heightened federal supply-chain scrutiny on networked devices from China-based manufacturers.

The advisory, published September 24, is the second ICS advisory this quarter from CISA flagging vulnerabilities in networked surveillance hardware, Digital Watchdog's VMAX DVR and NVR lineups received six CVEs on September 15. The Digital Watchdog advisory covered U.S.-headquartered products. This one is different: Eufy is a Shenzhen-based brand, and the vulnerabilities include the kind of flaws (hardcoded credentials, improper certificate validation) that supply-chain risk frameworks are explicitly designed to catch.

The most severe of the three is CVE-2026-93291, the certificate validation failure on the Omni C20. It carries a CVSS 3.1 base score of 9.4, with a network attack vector and no privileges or user interaction required. An attacker who can position themselves between the device and its update server can execute arbitrary code. That's the kind of vector that turns a camera into a pivot point.

CVE-2026-93289, the command injection during pairing, affects both the C20 and X10 Pro. It's rated 7.5 under CVSS 3.1 but gets a 9.0 under CVSS 4.0, the jump reflects the newer scoring system's higher weight on downstream impact when the compromised device sits on a shared network.

The advisory lists "Information Technology" as the critical infrastructure sector and "Worldwide" as deployment scope. What it doesn't say: whether any federal, state, or municipal agencies have these devices in inventory, whether Eufy has committed to a patch timeline beyond "upgrade to 1.6.4," or whether the hardcoded credentials have been rotated or merely documented in the new firmware.

Organizations running these devices should isolate them from business networks and block internet exposure where feasible, the standard CISA ICS boilerplate applies, but the boilerplate exists because the attack surface is real.


Published ·Deep Fathom