How do I update a Eufy Omni C20 or Omni X10 Pro to firmware version 1.6.4 or later?

If you have a Eufy Omni C20 or Omni X10 Pro, the practical answer is simple: Eufy recommends updating affected devices to firmware version 1.6.4 or later.
The CISA advisory confirms the target version, but it does not provide step-by-step update instructions in the available context.
What version should you update to?
Update to version 1.6.4 or later.
That recommendation applies because CISA’s September 24, 2026 advisory lists vulnerabilities affecting:
| Device | Affected versions named in the advisory |
|---|---|
| Eufy Omni C20 | Before 1.6.4 for CVE-2026-93289, CVE-2026-93290, and CVE-2026-93291 |
| Eufy Omni X10 Pro | Before 1.6.4 for CVE-2026-93289 |
How to handle the update
The confirmed guidance is to update the device firmware to 1.6.4 or newer. The advisory context does not confirm the exact menu path, app screen, or update method for installing that firmware.
So the safest practical approach is:
- Check your current firmware version.
- Look for an official firmware update option for the device.
- Install version 1.6.4 or later if it is available.
- Recheck the installed version after updating.
Why the update matters
CISA says successful exploitation could allow an attacker to run system-level commands or execute arbitrary code. The listed vulnerability types include OS command injection, hard-coded credentials, and improper certificate validation.
For CVE-2026-93289 specifically, the advisory says the products can be exposed to command injection during pairing by an unauthenticated attacker.
Because firmware guidance can change, check CISA’s advisory and Eufy’s official update information before relying on an older version number.
Which Eufy Omni C20 and Omni X10 Pro firmware versions are affected by the September 24, 2026 CISA advisory?

CISA’s September 24, 2026 advisory uses firmware version 1.6.4 as the cutoff for the affected Eufy Omni devices named in the advisory.
Affected firmware versions
| Product | Affected firmware according to CISA |
|---|---|
| Eufy Omni C20 | Versions before 1.6.4 for CVE-2026-93289, CVE-2026-93290, and CVE-2026-93291 |
| Eufy Omni X10 Pro | Versions before 1.6.4 for CVE-2026-93289 |
If your device is already on 1.6.4 or later, the available context says Eufy’s recommendation has been met. If it is below 1.6.4, it falls into the affected range described by CISA.
Which vulnerabilities are listed?
CISA names three vulnerability types in the advisory:
- OS command injection
- Hard-coded credentials
- Improper certificate validation
For CVE-2026-93289, CISA says an unauthenticated attacker could trigger command injection exposure during pairing.
What to check next
Check the firmware version shown on your device or in the official device management interface. The available context does not confirm the exact place where Eufy displays that version, so use the official product controls or announcement details rather than guessing.
Since advisories can be updated, compare your device against the latest official CISA notice before making a final call.
What should I do if my Eufy Omni C20 or Omni X10 Pro was paired while running firmware before 1.6.4?

If your Eufy Omni C20 or Omni X10 Pro was paired while running firmware before 1.6.4, the confirmed action is to update the device to firmware 1.6.4 or later.
CISA’s advisory specifically says CVE-2026-93289 can expose the products to command injection during pairing by an unauthenticated attacker.
The practical next step
Update the device firmware to 1.6.4 or newer.
That is the mitigation confirmed in the available context: Eufy recommends updating to version 1.6.4 or later.
What is confirmed about the pairing issue?
The advisory says:
- CVE-2026-93289 affects Eufy Omni C20 before 1.6.4.
- CVE-2026-93289 affects Eufy Omni X10 Pro before 1.6.4.
- The exposure can happen during pairing.
- The attacker described in the advisory is unauthenticated.
- Exploitation could allow system-level commands or arbitrary code execution.
The context does not confirm whether a device that was previously paired was actually exploited. It also does not provide a separate cleanup procedure beyond the firmware update recommendation.
What not to assume
Do not assume that pairing before 1.6.4 automatically means the device was compromised. The advisory describes a vulnerability and possible impact, not a confirmed incident on every affected device.
For the newest guidance, check the official advisory before taking additional steps beyond the confirmed update recommendation.
What changed in the CISA advisory for Eufy Omni C20 and Omni X10 Pro released on September 24, 2026?

CISA’s September 24, 2026 advisory added a clear security notice for Eufy Omni C20 and Omni X10 Pro devices, including affected firmware versions and the recommended update target.
What the advisory says changed
The advisory identifies vulnerabilities in:
- Eufy Omni C20 before firmware 1.6.4
- Eufy Omni X10 Pro before firmware 1.6.4, for CVE-2026-93289
For the Omni C20, CISA lists CVE-2026-93289, CVE-2026-93290, and CVE-2026-93291 as affecting versions before 1.6.4.
What kinds of vulnerabilities are involved?
CISA lists these vulnerability categories:
- OS command injection
- Hard-coded credentials
- Improper certificate validation
The advisory also says exploitation could allow system-level commands or arbitrary code execution.
One specific detail matters for pairing: for CVE-2026-93289, CISA says an unauthenticated attacker could expose the products to command injection during pairing.
What users are told to do
Eufy recommends updating to firmware version 1.6.4 or later.
That is the main practical takeaway from the advisory. If you are checking this after the release date, use the CISA page as the current reference point in case the advisory has been revised.
Sources / Learn more
Related reading
- What Starliner development changes did NASA and Boeing say they were planning?
- How can the public get tickets to meet NASA’s Artemis II crew at the Houston event?; What changed in NASA’s Sept. 28, 2026 update about the Artemis II Houston public event?; Who is the Houston public event for: Artemis II crew, Artemis Accords participants, or Crew-13 astronauts?
- What should NetScaler ADC and Gateway administrators do first after CISA added CVE-2026-88771 and CVE-2026-88772 to the KEV Catalog?; Which Citrix products are affected by CVE-2026-88771 and CVE-2026-88772?; How are CVE-2026-88771 and CVE-2026-88772 different?; When did CISA add the two Citrix NetScaler vulnerabilities to the Known Exploited Vulnerabilities Catalog?
- When does Frugal Fannie’s Fashion Warehouse’s going-out-of-business sale start, and how much time do shoppers have before the Westwood store closes for good?

Leave a Reply