CVE Feed

    Dashboard / CVE / CVE-2025-32878

    CVE-2025-32878

    An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. This function is mainly for downloading firmware files. Before downloading firmware files, the watch requests some information about the firmware via HTTPS from the back-end API. However, the X.509 server certificate within the TLS handshake is not validated by the device. This allows an attacker within an active machine-in-the-middle position, using a TLS proxy and a self-signed certificate, to eavesdrop and manipulate the HTTPS communication. This could be abused, for example, for stealing the API access token of the assigned user account.

    Published:Jun 20, 2025
    Last Modified:Jul 8, 2025
    EPS:Jun 20, 2025
    EPSS Score:0.00043
    CVSS Score:9.8

    Affected Products

    Vendor
    Yftech
    Product
    Coros Pace 3
    Vendor
    Yftech
    Product
    Coros Pace 3 Firmware

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High