CISA Issues Security Advisory for Eufy Omni C20 and X10 Pro Omni Robot Vacuums
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a security advisory regarding vulnerabilities found in Eufy Omni C20 and X10 Pro Omni robot vacuums. CISA identified three specific flaws in the Omni C20, one of which also affects the X10 Pro Omni. These vulnerabilities include a flaw in the pairing process that could allow an unauthenticated attacker to execute system commands, hard-coded credentials in the Omni C20 that could grant access to sensitive information like mapping data, and improper certificate validation in the C20 that could enable interception of communications and arbitrary code execution. Eufy recommends that owners update their devices to firmware version 1.6.4 or later to mitigate these risks. CISA has not received reports of these vulnerabilities being actively exploited.