[Eufy Omni C20, Omni X10 Pro]: Eufy Omni C20 and Omni X10 Pro CISA Advisory: Firmware 1.6.4, Affected Versions, and Pairing Risk

Close-up of a spherical smart speaker with illuminated base, perfect for modern interiors.

How do I update a Eufy Omni C20 or Omni X10 Pro to firmware version 1.6.4 or later?

Close-up of a spherical smart speaker with illuminated base, perfect for modern interiors.

If you have a Eufy Omni C20 or Omni X10 Pro, the practical answer is simple: Eufy recommends updating affected devices to firmware version 1.6.4 or later.

The CISA advisory confirms the target version, but it does not provide step-by-step update instructions in the available context.

What version should you update to?

Update to version 1.6.4 or later.

That recommendation applies because CISA’s September 24, 2026 advisory lists vulnerabilities affecting:

Device Affected versions named in the advisory
Eufy Omni C20 Before 1.6.4 for CVE-2026-93289, CVE-2026-93290, and CVE-2026-93291
Eufy Omni X10 Pro Before 1.6.4 for CVE-2026-93289

How to handle the update

The confirmed guidance is to update the device firmware to 1.6.4 or newer. The advisory context does not confirm the exact menu path, app screen, or update method for installing that firmware.

So the safest practical approach is:

  1. Check your current firmware version.
  2. Look for an official firmware update option for the device.
  3. Install version 1.6.4 or later if it is available.
  4. Recheck the installed version after updating.

Why the update matters

CISA says successful exploitation could allow an attacker to run system-level commands or execute arbitrary code. The listed vulnerability types include OS command injection, hard-coded credentials, and improper certificate validation.

For CVE-2026-93289 specifically, the advisory says the products can be exposed to command injection during pairing by an unauthenticated attacker.

Because firmware guidance can change, check CISA’s advisory and Eufy’s official update information before relying on an older version number.

Which Eufy Omni C20 and Omni X10 Pro firmware versions are affected by the September 24, 2026 CISA advisory?

Close-up of a hand holding black wireless Bluetooth earbuds with a yellow backdrop.

CISA’s September 24, 2026 advisory uses firmware version 1.6.4 as the cutoff for the affected Eufy Omni devices named in the advisory.

Affected firmware versions

Product Affected firmware according to CISA
Eufy Omni C20 Versions before 1.6.4 for CVE-2026-93289, CVE-2026-93290, and CVE-2026-93291
Eufy Omni X10 Pro Versions before 1.6.4 for CVE-2026-93289

If your device is already on 1.6.4 or later, the available context says Eufy’s recommendation has been met. If it is below 1.6.4, it falls into the affected range described by CISA.

Which vulnerabilities are listed?

CISA names three vulnerability types in the advisory:

  • OS command injection
  • Hard-coded credentials
  • Improper certificate validation

For CVE-2026-93289, CISA says an unauthenticated attacker could trigger command injection exposure during pairing.

What to check next

Check the firmware version shown on your device or in the official device management interface. The available context does not confirm the exact place where Eufy displays that version, so use the official product controls or announcement details rather than guessing.

Since advisories can be updated, compare your device against the latest official CISA notice before making a final call.

What should I do if my Eufy Omni C20 or Omni X10 Pro was paired while running firmware before 1.6.4?

Man in yellow sweater using smartphone, robotic vacuum on wooden floor, modern home setting.

If your Eufy Omni C20 or Omni X10 Pro was paired while running firmware before 1.6.4, the confirmed action is to update the device to firmware 1.6.4 or later.

CISA’s advisory specifically says CVE-2026-93289 can expose the products to command injection during pairing by an unauthenticated attacker.

The practical next step

Update the device firmware to 1.6.4 or newer.

That is the mitigation confirmed in the available context: Eufy recommends updating to version 1.6.4 or later.

What is confirmed about the pairing issue?

The advisory says:

  • CVE-2026-93289 affects Eufy Omni C20 before 1.6.4.
  • CVE-2026-93289 affects Eufy Omni X10 Pro before 1.6.4.
  • The exposure can happen during pairing.
  • The attacker described in the advisory is unauthenticated.
  • Exploitation could allow system-level commands or arbitrary code execution.

The context does not confirm whether a device that was previously paired was actually exploited. It also does not provide a separate cleanup procedure beyond the firmware update recommendation.

What not to assume

Do not assume that pairing before 1.6.4 automatically means the device was compromised. The advisory describes a vulnerability and possible impact, not a confirmed incident on every affected device.

For the newest guidance, check the official advisory before taking additional steps beyond the confirmed update recommendation.

What changed in the CISA advisory for Eufy Omni C20 and Omni X10 Pro released on September 24, 2026?

Aerial shot of the urban landscape of Belo Horizonte, showcasing its iconic architecture and bustling cityscape.

CISA’s September 24, 2026 advisory added a clear security notice for Eufy Omni C20 and Omni X10 Pro devices, including affected firmware versions and the recommended update target.

What the advisory says changed

The advisory identifies vulnerabilities in:

  • Eufy Omni C20 before firmware 1.6.4
  • Eufy Omni X10 Pro before firmware 1.6.4, for CVE-2026-93289

For the Omni C20, CISA lists CVE-2026-93289, CVE-2026-93290, and CVE-2026-93291 as affecting versions before 1.6.4.

What kinds of vulnerabilities are involved?

CISA lists these vulnerability categories:

  • OS command injection
  • Hard-coded credentials
  • Improper certificate validation

The advisory also says exploitation could allow system-level commands or arbitrary code execution.

One specific detail matters for pairing: for CVE-2026-93289, CISA says an unauthenticated attacker could expose the products to command injection during pairing.

What users are told to do

Eufy recommends updating to firmware version 1.6.4 or later.

That is the main practical takeaway from the advisory. If you are checking this after the release date, use the CISA page as the current reference point in case the advisory has been revised.

Sources / Learn more

Related reading

Comments

Leave a Reply

[privacy-do-not-sell-link]

Discover more from Trending Issues Daily

Subscribe now to keep reading and get access to the full archive.

Continue reading