Man-in-the-Middle Certificate Validation Flaw in Eufy Omni C20 Enables Code Execution
AI analysis
The Eufy Omni C20 network-connected robot vacuum fails to properly validate TLS certificates (CWE-295), allowing an attacker who can intercept the device's network traffic to impersonate a legitimate server in a man-in-the-middle attack. Because the device accepts a forged certificate, the attacker can tamper with traffic such as firmware or data exchanges and ultimately execute arbitrary code on the vacuum itself. The flaw carries a CVSS 4.0 score of 9.3 (critical) with a network attack vector, no privileges or user interaction required, though in practice the attacker must first obtain a man-in-the-middle position on the victim's network or traffic path. Owners of the Omni C20 are directly affected, and related reporting also names the Eufy Omni X10 Pro. There is no known public proof-of-concept, the issue is not on the CISA KEV list, and no exploitation has been reported to date.
What to do: Update the Omni C20 (and Omni X10 Pro) firmware to the latest version through the Eufy app as soon as the vendor releases a fix, since unpatched devices will accept a forged server certificate. Until then, place the vacuum on a segmented guest network or isolated VLAN away from PCs and other sensitive devices, and never operate or provision it over public or untrusted Wi-Fi. Check the CISA ICS advisory (ics-cert@hq.dhs.gov) and Anker/Eufy security notices for the specific patched firmware versions when published.
Affected
| Anker (Eufy) Omni C20 | — |
| Anker (Eufy) Omni X10 Pro | — |
Estimated exposure
moderatetens of thousands of devices/households (order of 10k–100k+ units across both models) — These are specific consumer robot vacuum models from a major brand (Anker/Eufy) whose typical per-model unit sales fall in the tens of thousands to low hundreds of thousands; exact sales and active-install figures are not published, and…