Command Injection Vulnerability in ABC Tech Smart Devices
CVE-2026-93289

9CRITICAL

Key Information:

Vendor

Eufy

Vendor
CVE Published:
24 September 2026

What is CVE-2026-93289?

This vulnerability allows an unauthenticated attacker to exploit command injection during the device pairing process of ABC Tech's smart devices. By manipulating inputs, an attacker could execute arbitrary system commands, posing serious security risks to devices and potentially compromising sensitive user data.

Affected Version(s)

Omni C20 0 < 1.6.4

Omni X10 Pro 0 < 1.6.4

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jared of Somerset Recon reported these vulnerabilities to CISA.
.