Eufy Omni C20, Omni X10 Pro
Summary
Multiple vulnerabilities have been identified in Eufy Omni C20 and Omni X10 Pro devices, specifically versions prior to 1.6.4. Successful exploitation of these flaws could allow an unauthenticated attacker to execute system commands or arbitrary code during the pairing process.
IFF Assessment
The identified vulnerabilities allow for command injection and execution of arbitrary code, posing a significant risk to the integrity and confidentiality of affected devices and potentially the network they reside on.
Severity
The CVSS score of 9.0 (CRITICAL) is assigned based on the provided vector string for CVSS v4.0, indicating a critical severity. The attack vector is 'Adjacent' (AV:A), indicating the attacker needs physical proximity or local network access, 'High' complexity (AC:H) suggesting a challenging exploit, 'No Privileges Required' (PR:N), and 'No User Interaction' (UI:N). The impact on Confidentiality, Integrity, and Availability is 'High' (C:H/I:H/A:H), meaning sensitive data can be accessed, modified, or systems can be made unavailable.
Defender Context
Defenders should prioritize patching or upgrading affected Eufy Omni devices to version 1.6.4 or later to mitigate the risk of command injection attacks. Network segmentation and vigilant monitoring for unusual activity during device pairing processes are also recommended as proactive defense measures.