omni_c20 vulnerabilities
CVEs whose affected-version data names the omni_c20 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-93291Critical· 9.4Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
▾ MidnightEufy · Omni C20via NVD
CVE-2026-93290Medium· 5.5Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.
Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.
▾ SunlitEufy · Omni C20via NVD
CVE-2026-93289High· 7.5The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.
The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.
▾ TwilightEufy · Omni C20via NVD