Owners of two Eufy robot vacuums should check their firmware versions after a federal security advisory identified vulnerabilities in the Omni C20 and X10 Pro Omni. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) says devices running firmware older than version 1.6.4 are affected. Eufy recommends updating to version 1.6.4 or later.
The advisory, published September 24, describes three vulnerabilities in the Omni C20. One of those also affects the X10 Pro Omni, which CISA lists as the “Omni X10 Pro.” CISA says it has received no reports of known public exploitation specifically targeting these vulnerabilities.
What did CISA find?
Both models are affected by a flaw in the pairing process that could let an unauthenticated attacker execute system commands. The other two findings apply to the Omni C20: hard-coded credentials could help an attacker gain access to information such as mapping data, and improper certificate validation could allow an attacker to intercept the robot’s communications and execute arbitrary code.
The certificate-validation vulnerability in the C20 received a 9.4 out of 10 severity score. That score applies to the C20 finding; it does not mean every vulnerability in both robots carries a 9.4 rating.
These are potential security risks, not a report that owners’ maps have been accessed or their vacuums taken over. The useful next step is to confirm which firmware version is actually installed.
What should Eufy owners do?
If you have an Omni C20 or X10 Pro Omni, open the eufy Clean app, select your robot, and check Settings > Firmware Update for its installed version and any available update. If the version is older than 1.6.4, install the update and check the displayed version again afterward.
Eufy says the X10 Pro Omni normally checks for updates automatically in the early morning when it has a stable 2.4 GHz Wi-Fi connection. Its support instructions explain how to enable Auto Upgrade under Settings > Firmware Update. It is still worth checking the installed version directly rather than assuming an automatic update succeeded. If an affected robot remains below 1.6.4 and the app offers no update, contact Eufy support for guidance.
The advisory names only the Omni C20 and X10 Pro Omni. It does not establish that other Eufy robot vacuums are affected. Questions for Eufy include when the corrected firmware began rolling out, how many affected devices have received it, and whether the same pairing or certificate code is used in other models.
Robot Vacuum Security: What Users Should Know
Learn how cameras, microphones, mapping data, cloud connections, and software vulnerabilities can affect robot vacuum privacy and security.
Top 20 Robot Vacuums
Explore Vacuum Wars’ always up-to-date rankings of the best robot vacuums, based on independent, hands-on testing. We purchase every unit ourselves and have evaluated more than 150 models, giving us a deep benchmark for cleaning performance, navigation, battery life, and advanced features like obstacle avoidance and mopping.



