Hard-Coded Credentials Vulnerability in Omni C20 by Omni
CVE-2026-93290

6.8MEDIUM

Key Information:

Vendor

Eufy

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-93290?

The Omni C20 has been identified to contain a vulnerability due to the presence of hard-coded credentials. This flaw enables attackers to potentially monitor log files, where they could extract sensitive information, including access credentials and mapping data. Organizations using the Omni C20 should take immediate action to assess their exposure and implement measures to secure their systems against unauthorized access.

Affected Version(s)

Omni C20 0 < 1.6.4

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jared of Somerset Recon reported these vulnerabilities to CISA.
.