CVE-2025-32877 is a critical vulnerability affecting COROS PACE 3 devices running firmware through version 3.0808.0. The flaw stems from the device's use of the "Just Works" Bluetooth Low Energy (BLE) pairing method, which lacks authentication. This allows for unauthenticated interaction and machine-in-the-middle (MitM) attacks. With a CVSS score of 9.8 (CRITICAL), this vulnerability poses a significant risk, enabling attackers to achieve high confidentiality, integrity, and availability impacts without user interaction. There is currently no public exploit code available, and it is not listed on CISA's KEV catalog, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0808.0CPE matchmatch criteria | cpe:2.3:o:yftech:coros_pace_3_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.