CVE-2026-93289

Summary

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

Affected Software

VendorProductVersion RangeStatus
EufyOmni C200 < 1.6.4affected
EufyOmni X10 Pro0 < 1.6.4affected

Weaknesses

  • CWE-78: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References