Yftech maintains a narrowly focused product line centered on the COROS Pace 3 wearable device and its firmware, where vulnerabilities skew strongly toward critical-severity outcomes. The recurring exposure reflects authentication and certificate-validation weaknesses common to connected devices with remote communication or cloud-synchronization features, alongside cleartext-transmission issues that amplify the impact of weak or missing authentication controls. Defenders should prioritize firmware updates for this device and restrict network access where feasible; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yftech over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-32880CRITICAL An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access, the COROS Pace 3 downloads firmware fil | Jun 20, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-32877CRITICAL An issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, which results in the use of the Just Works | Jun 20, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-48706CRITICAL An issue was discovered in COROS PACE 3 through 3.0808.0. Due to an out-of-bounds read vulnerability, sending a crafted BLE message forces the device to reboot. | Jun 20, 2025 | 9.1 | 25 | NO | NO |
CVE-2025-32878CRITICAL An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. This function is mainly for downloading firmware files. B | Jun 20, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-32879HIGH An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allows an attacker to connect with the device | Jun 20, 2025 | 8.8 | 23 | NO | NO |
CVE-2025-48705HIGH An issue was discovered in COROS PACE 3 through 3.0808.0. Due to a NULL pointer dereference vulnerability, sending a crafted BLE message forces the device to reboot. | Jun 20, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-32876MEDIUM An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure Connections and instead enforces BLE Leg | Jun 20, 2025 | 6.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yftech.
Media articles that mention a CVE ID that affects a product developed by Yftech — matched by CVE ID, not by vendor name.