U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-32876

Change History

New CVE Received from MITRE 6/20/2025 10:15:27 AM

Action Type Old Value New Value
Added Description

								
							
							
						
An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure Connections and instead enforces BLE Legacy Pairing. In BLE Legacy Pairing, the Short-Term Key (STK) can be easily guessed. This requires knowledge of the Temporary Key (TK), which, in the case of the COROS Pace 3, is set to 0 due to the Just Works pairing method. An attacker within Bluetooth range can therefore perform sniffing attacks, allowing eavesdropping on the communication.
Added Reference

								
							
							
						
https://support.coros.com/hc/en-us/articles/20087694119828-COROS-PACE-3-Release-Notes
Added Reference

								
							
							
						
https://syss.de
Added Reference

								
							
							
						
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-023.txt