CVE Feed

    Dashboard / CVE / CVE-2025-32876

    CVE-2025-32876

    An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure Connections and instead enforces BLE Legacy Pairing. In BLE Legacy Pairing, the Short-Term Key (STK) can be easily guessed. This requires knowledge of the Temporary Key (TK), which, in the case of the COROS Pace 3, is set to 0 due to the Just Works pairing method. An attacker within Bluetooth range can therefore perform sniffing attacks, allowing eavesdropping on the communication.

    Published:Jun 20, 2025
    Last Modified:Jul 8, 2025
    EPS:Jun 20, 2025
    EPSS Score:0.0003
    CVSS Score:6.8

    Affected Products

    Vendor
    Yftech
    Product
    Coros Pace 3
    Vendor
    Yftech
    Product
    Coros Pace 3 Firmware

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High