Coros Pace 3
Vendor:
First CVE: Jun 20, 2025 · Active for 1 year
7
Total CVEs
More Total CVEs than 83% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
8.8
Avg CVSS
Higher Avg CVSS than 79% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Coros Pace 3 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 20, 2025
13 months ago
Most Recent CVE
Jun 20, 2025
399 days ago
CVE Severity & Scoring
Coros Pace 37 CVEs
14%
29%
57%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (71.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (28.6%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-32880CRITICAL An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access, the COROS Pace 3 downloads firmware fil | Jun 20, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-32877CRITICAL An issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, which results in the use of the Just Works | Jun 20, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-48706CRITICAL An issue was discovered in COROS PACE 3 through 3.0808.0. Due to an out-of-bounds read vulnerability, sending a crafted BLE message forces the device to reboot. | Jun 20, 2025 | 9.1 | 25 | NO | NO |
CVE-2025-32878CRITICAL An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. This function is mainly for downloading firmware files. B | Jun 20, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-32879HIGH An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allows an attacker to connect with the device | Jun 20, 2025 | 8.8 | 23 | NO | NO |
CVE-2025-48705HIGH An issue was discovered in COROS PACE 3 through 3.0808.0. Due to a NULL pointer dereference vulnerability, sending a crafted BLE message forces the device to reboot. | Jun 20, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-32876MEDIUM An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure Connections and instead enforces BLE Leg | Jun 20, 2025 | 6.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Coros Pace 3
Top CWEs
Versions
No cataloged versions.