Skip to content
Saved

A Eufy robot vacuum bug lets anyone run commands on it without a password

CISA disclosed three flaws in two Eufy robot vacuums, the worst letting an attacker on the same network intercept the device and run code on it.

By Robovations2 min read

A dark robot vacuum runs down the runner of a tiled entry hall, past a shoe bench where the home router sits with its lights on, toward a front door that is bolted and on its chain.

On September 24, 2026, the Cybersecurity and Infrastructure Security Agency published an advisory on three vulnerabilities in eufy’s Omni C20 and RoboVac X10 Pro Omni robot vacuums. One flaw sits in the pairing process on both machines. An attacker with no username or password can use it to send the vacuum system-level commands. CISA scored it 7.5 out of 10.

A dark robot vacuum sits on a living-room floor just out of its opened delivery box, a foam packing end-cap on the floor, in front of its new wash station plugged in against the wall. The pairing button on its lid is picked out, and the home router stands on a sideboard nearby.
The flaw sits in the pairing process on both machines, and an attacker with no username or password can use it to send the vacuum system-level commands.

Two more flaws apply only to the Omni C20. One stores credentials in a fixed, hardcoded form, and anyone who can read the device’s log files could pull them out and reach a household’s floor maps. CISA rated that one 5.5.

The other is a certificate check the vacuum is supposed to run and does not. An attacker already on the same network could intercept its traffic and execute code on the device as a result. CISA scored it 9.4, the highest of the three.

eufy’s parent company, Anker, has patched all three in firmware 1.6.4. Both vacuums can install it on their own if a household has turned on Auto Upgrade inside the eufy Clean app. CISA credits the find to an outside security researcher.

The advisory describes what the flaws would allow. CISA states it has received no reports of any of the three being exploited anywhere.

A write-up for owners summarized the advisory this way: “These are potential security risks, not a report that owners’ maps have been accessed or their vacuums taken over.” A separate technical write-up of the advisory noted that no proof-of-concept code has been published.

The fix only helps a vacuum that installs it. A machine with Auto Upgrade switched off, or one nobody has updated by hand, is still running the code CISA described as exploitable by an attacker holding no credentials at all.

Published October 1, 2026Send a correction