Command Injection Vulnerability in ABC Tech Smart Devices
CVE-2026-93289
9CRITICAL
What is CVE-2026-93289?
This vulnerability allows an unauthenticated attacker to exploit command injection during the device pairing process of ABC Tech's smart devices. By manipulating inputs, an attacker could execute arbitrary system commands, posing serious security risks to devices and potentially compromising sensitive user data.
Affected Version(s)
Omni C20 0 < 1.6.4
Omni X10 Pro 0 < 1.6.4
References
CVSS V4
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jared of Somerset Recon reported these vulnerabilities to CISA.
