Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Eufy recommends users to upgrade to version 1.6.4 or later.
Workaround
No workaround given by the vendor.
References
History
Thu, 24 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code. | |
| Title | Improper certificate validation in Eufy Omni C20 | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-24T19:33:34.326Z
Reserved: 2026-09-17T16:04:34.684Z
Link: CVE-2026-93291
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses