Impact
This vulnerability is an improper certificate validation flaw that permits a man‑in‑the‑middle attack, allowing an attacker to inject malicious certificates and potentially execute arbitrary code on the device. It is classified as CWE‑295 and presents a severe compromise of both confidentiality and integrity of the device’s communications.
Affected Systems
All Eufy Omni C20 devices running firmware versions earlier than 1.6.4 are affected. The vendor lists Omni C20 as the impacted product line. Updating to the latest firmware, which is 1.6.4 or later, includes the required certificate validation logic.
Risk and Exploitability
The CVSS score of 9.3 signals a critical threat, while the absence of an EPSS value indicates no publicly available exploitation data yet and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a compromised network or a rogue device that can intercept traffic to the Omni C20, and the attacker can exploit the certificate validation failure to inject malicious payloads. The high severity suggests that exploitation, should it become available, would be very damaging to the affected devices.
OpenCVE Enrichment