« Volver al listado

Yftech

Yftech Coros Pace 3 Firmware: vulnerabilidades y CVE

Yftech Coros Pace 3 Firmware tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses0
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-48706Crítica (9.1)0.59%—20 jun 2025
An issue was discovered in COROS PACE 3 through 3.0808.0. Due to an out-of-bounds read vulnerability, sending a crafted BLE message forces the device to reboot.
CVE-2025-48705Alta (7.5)0.51%—20 jun 2025
An issue was discovered in COROS PACE 3 through 3.0808.0. Due to a NULL pointer dereference vulnerability, sending a crafted BLE message forces the device to reboot.
CVE-2025-32880Crítica (9.8)0.45%—20 jun 2025
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access, the COROS Pace 3 downloads firmware files via HTTP. However, the communication…
CVE-2025-32879Alta (8.8)0.53%—20 jun 2025
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allows an attacker to connect with the device via BLE if no other device is…
CVE-2025-32878Crítica (9.8)0.41%—20 jun 2025
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. This function is mainly for downloading firmware files. Before downloading firmware files, the…
CVE-2025-32877Crítica (9.8)0.71%—20 jun 2025
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, which results in the use of the Just Works pairing method. This method does not…
CVE-2025-32876Media (6.8)0.40%—20 jun 2025
An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure Connections and instead enforces BLE Legacy Pairing. In BLE Legacy Pairing, the…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application5
  2. T1499.004 Application or System Exploitation2
  3. T1078 Valid Accounts1
  4. T1078.001 Default Accounts1
  5. T1210 Exploitation of Remote Services1
  6. T1557 Adversary-in-the-Middle1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.