Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical OS Command Injection (CVE‑2026‑93289/93290/93291) in Eufy Omni C20 & Omni X10 Pro Enables Remote Code Execution

CISA reports three CVEs affecting Eufy Omni C20 and X10 Pro firmware < 1.6.4 that permit unauthenticated attackers to run system commands during pairing. The CVSS score of 9.4 makes immediate remediation essential, and the flaws underscore the need for robust patch‑management controls for audit readiness.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
cisa.gov

Critical OS Command Injection (CVE‑2026‑93289/93290/93291) in Eufy Omni C20 & Omni X10 Pro Enables Remote Code Execution

What It Is – The U.S. Cybersecurity & Infrastructure Security Agency (CISA) issued an advisory (ICS‑A‑26‑267‑02) identifying three critical‑severity vulnerabilities in the firmware of Eufy Omni C20 and Omni X10 Pro devices (versions < 1.6.4). The flaws include OS command injection, hard‑coded credentials, and improper certificate validation, allowing an unauthenticated attacker to execute arbitrary system commands during the device‑pairing process.

Exploitability – The vulnerabilities are publicly disclosed, have a CVSS v3 base score of 9.4, and can be exploited without authentication. No public exploit code has been released, but the severity and ease of exploitation warrant immediate remediation.

Affected Products – Eufy Omni C20 < 1.6.4 and Omni X10 Pro < 1.6.4 (consumer‑grade smart‑home security hubs).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a secure configuration and patch‑management control that provides continuous evidence of firmware version compliance across deployed assets.
  • Highlights the importance of credential hygiene (eliminating hard‑coded secrets) as a control objective that maps to multiple frameworks (e.g., NIST CSF, ISO 27001).
  • Supports a defensible audit trail: documenting timely upgrades and verification of certificate handling shows due diligence to regulators and enterprise buyers.

Recommended Actions

  • Upgrade all Omni C20 and X10 Pro devices to firmware 1.6.4 or later immediately.
  • Verify that device certificates are validated correctly after the upgrade.
  • Integrate automated firmware‑version monitoring into your asset‑inventory system to capture continuous compliance evidence.
  • Record remediation steps in your control‑evidence repository to support audit readiness.

Source: CISA Advisory – ICS‑A‑26‑267‑02

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-02 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →