PT-2025-26315 · Coros · Coros Pace 3

Moritz Abrell

·

Published

2025-06-20

·

Updated

2025-07-08

·

CVE-2025-32879

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: COROS PACE 3 versions 3.0808.0 and earlier
Description: An issue was discovered that allows an attacker to connect to the device via Bluetooth Low Energy (BLE) if no other device is connected. Once connected, the attacker can access the device's BLE services and characteristics without any authentication or security level, enabling them to configure the device, send notifications, reset the device to factory settings, or install software.
Recommendations: For COROS PACE 3 versions 3.0808.0 and earlier, as a temporary workaround, consider disabling the Bluetooth advertising feature when no device is connected to minimize the risk of exploitation. Restrict access to the device's BLE services and characteristics to prevent unauthorized configuration or control.

Exploit

Fix

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-32879

Affected Products

Coros Pace 3