Description
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
Published: 2026-09-24
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution via Man-in-the-Middle
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an improper certificate validation flaw that permits a man‑in‑the‑middle attack, allowing an attacker to inject malicious certificates and potentially execute arbitrary code on the device. It is classified as CWE‑295 and presents a severe compromise of both confidentiality and integrity of the device’s communications.

Affected Systems

All Eufy Omni C20 devices running firmware versions earlier than 1.6.4 are affected. The vendor lists Omni C20 as the impacted product line. Updating to the latest firmware, which is 1.6.4 or later, includes the required certificate validation logic.

Risk and Exploitability

The CVSS score of 9.3 signals a critical threat, while the absence of an EPSS value indicates no publicly available exploitation data yet and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a compromised network or a rogue device that can intercept traffic to the Omni C20, and the attacker can exploit the certificate validation failure to inject malicious payloads. The high severity suggests that exploitation, should it become available, would be very damaging to the affected devices.

Generated by OpenCVE AI on September 25, 2026 at 03:15 UTC.

Remediation

Vendor Solution

Eufy recommends users to upgrade to version 1.6.4 or later.


OpenCVE Recommended Actions

  • Upgrade the device to firmware 1.6.4 or later to include proper certificate validation.
  • If an immediate firmware update is not possible, isolate the Omni C20 from external networks or disable remote management features to limit exposure to a potential man‑in‑the‑middle attack.
  • Monitor device logs and network traffic for anomalous certificate activity, and restrict the device’s trusted certificate store if possible.

Generated by OpenCVE AI on September 25, 2026 at 03:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
Title Improper certificate validation in Eufy Omni C20
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-24T19:33:34.326Z

Reserved: 2026-09-17T16:04:34.684Z

Link: CVE-2026-93291

cve-icon Vulnrichment

Updated: 2026-09-24T19:33:30.719Z

cve-icon NVD

Status : Deferred

Published: 2026-09-24T20:17:34.463

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-93291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T03:30:08Z

Weaknesses
  • CWE-295

    Improper Certificate Validation