A Eufy robot vacuum bug lets anyone run commands on it without a password
CISA disclosed three flaws in two Eufy robot vacuums, the worst letting an attacker on the same network intercept the device and run code on it.

On September 24, 2026, the Cybersecurity and Infrastructure Security Agency published an advisory on three vulnerabilities in eufy’s Omni C20 and RoboVac X10 Pro Omni robot vacuums. One flaw sits in the pairing process on both machines. An attacker with no username or password can use it to send the vacuum system-level commands. CISA scored it 7.5 out of 10.

Two more flaws apply only to the Omni C20. One stores credentials in a fixed, hardcoded form, and anyone who can read the device’s log files could pull them out and reach a household’s floor maps. CISA rated that one 5.5.
The other is a certificate check the vacuum is supposed to run and does not. An attacker already on the same network could intercept its traffic and execute code on the device as a result. CISA scored it 9.4, the highest of the three.
eufy’s parent company, Anker, has patched all three in firmware 1.6.4. Both vacuums can install it on their own if a household has turned on Auto Upgrade inside the eufy Clean app. CISA credits the find to an outside security researcher.
The advisory describes what the flaws would allow. CISA states it has received no reports of any of the three being exploited anywhere.
A write-up for owners summarized the advisory this way: “These are potential security risks, not a report that owners’ maps have been accessed or their vacuums taken over.” A separate technical write-up of the advisory noted that no proof-of-concept code has been published.
The fix only helps a vacuum that installs it. A machine with Auto Upgrade switched off, or one nobody has updated by hand, is still running the code CISA described as exploitable by an attacker holding no credentials at all.


