CVE-2025-32877
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
20/06/2025
Last modified:
08/07/2025
Description
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, which results in the use of the Just Works pairing method. This method does not implement any authentication, which therefore allows machine-in-the-middle attacks. Furthermore, this lack of authentication allows attackers to interact with the device via BLE without requiring prior authorization.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:yftech:coros_pace_3_firmware:*:*:*:*:*:*:*:* | 3.0808.0 (including) | |
| cpe:2.3:h:yftech:coros_pace_3:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



