Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.59% | — | Yftech Coros Pace 3 Firmware | 20/6/2025 | 17/6/2026 | An issue was discovered in COROS PACE 3 through 3.0808.0. Due to an out-of-bounds read vulnerability, sending a crafted BLE message forces the device to reboot. | |
| Analizada | Alta (7.5) | 0.51% | — | Yftech Coros Pace 3 Firmware | 20/6/2025 | 17/6/2026 | An issue was discovered in COROS PACE 3 through 3.0808.0. Due to a NULL pointer dereference vulnerability, sending a crafted BLE message forces the device to reboot. | |
| Analizada | Crítica (9.8) | 0.45% | — | Yftech Coros Pace 3 Firmware | 20/6/2025 | 17/6/2026 | An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access, the COROS Pace 3 downloads firmware files via HTTP. However, the communication is not encrypted and allows sniffing and machine-in-the-middle attacks. | |
| Analizada | Alta (8.8) | 0.53% | — | Yftech Coros Pace 3 Firmware | 20/6/2025 | 17/6/2026 | An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allows an attacker to connect with the device via BLE if no other device is connected. While connected, none of the BLE services and characteristics of the device require any… | |
| Analizada | Crítica (9.8) | 0.41% | — | Yftech Coros Pace 3 Firmware | 20/6/2025 | 17/6/2026 | An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. This function is mainly for downloading firmware files. Before downloading firmware files, the watch requests some information about the firmware via HTTPS from the back-end API. However, the… | |
| Analizada | Crítica (9.8) | 0.71% | — | Yftech Coros Pace 3 Firmware | 20/6/2025 | 17/6/2026 | An issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, which results in the use of the Just Works pairing method. This method does not implement any authentication, which therefore allows machine-in-the-middle attacks. Furthermore, this… | |
| Analizada | Media (6.8) | 0.40% | — | Yftech Coros Pace 3 Firmware | 20/6/2025 | 17/6/2026 | An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure Connections and instead enforces BLE Legacy Pairing. In BLE Legacy Pairing, the Short-Term Key (STK) can be easily guessed. This requires knowledge of the Temporary Key (TK),… |