AI analysis
The Eufy (Anker) Omni C20 robot vacuum — with related coverage also naming the Omni X10 Pro — ships with hard-coded credentials (CWE-798) that are additionally exposed in log files. An attacker with local access and low privileges can monitor the device's logs to harvest these credentials, then use them to access information such as the home mapping (floor plan) data associated with the vacuum. The vulnerability is rated medium severity (CVSS 4.0: 6.8) with a local attack vector, low attack complexity, and no user interaction required, so it primarily matters where an adversary already has some local access to the device or its data. Owners of the affected consumer robot vacuum models are the impacted population. There is no known public proof-of-concept, the flaw is not in the CISA Known Exploited Vulnerabilities catalog, and no exploitation has been reported.
What to do: Install the latest firmware for the Omni C20 (and Omni X10 Pro if owned) through the Eufy mobile app and monitor the CISA ICS advisory for patched versions, since no fixed version numbers were provided in the initial disclosure. Treat device and companion-app logs as sensitive — restrict local and app-level access to the vacuum, and avoid sharing diagnostic logs or leaving debug logging enabled. If logs were previously shared or the device was handled by untrusted parties, re-link the vacuum to your account and change the associated Eufy account password to rotate any exposed credentials.
Affected
| Eufy (Anker Innovations) Omni C20 | — |
| Eufy (Anker Innovations) Omni X10 Pro | — |
Estimated exposure
nicheunknown; plausibly on the order of tens of thousands of households — No public sales, install-count, or scan data exists for these specific consumer vacuum models; single-model consumer appliances from a mid-tier brand typically ship in the tens of thousands of units, and the flaw is locally exploitable…