PT-2025-26315 · Coros · Coros Pace 3
Moritz Abrell
·
Published
2025-06-20
·
Updated
2025-07-08
·
CVE-2025-32879
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
COROS PACE 3 versions 3.0808.0 and earlier
Description:
An issue was discovered that allows an attacker to connect to the device via Bluetooth Low Energy (BLE) if no other device is connected. Once connected, the attacker can access the device's BLE services and characteristics without any authentication or security level, enabling them to configure the device, send notifications, reset the device to factory settings, or install software.
Recommendations:
For COROS PACE 3 versions 3.0808.0 and earlier, as a temporary workaround, consider disabling the Bluetooth advertising feature when no device is connected to minimize the risk of exploitation. Restrict access to the device's BLE services and characteristics to prevent unauthorized configuration or control.
Exploit
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coros Pace 3