CRITICAL🇵🇱 Wersja polska

CVE-2025-48706

CVSS 9.1v3.1pub. 2025-06-20upd. 2025-07-08

An issue was discovered in COROS PACE 3 through 3.0808.0. Due to an out-of-bounds read vulnerability, sending a crafted BLE message forces the device to reboot.

🤖 AI Analysis
How it works

An attacker within Bluetooth Low Energy (BLE) range sends a specially crafted BLE message to the device. The device firmware performs a data read outside the boundaries of the allocated memory buffer (out-of-bounds read), which leads to system instability and forces the smartwatch to reboot. The attack does not require prior authentication or user interaction.

Impact

An attacker can remotely restart the device multiple times, causing persistent unavailability of smartwatch functions (denial of service, DoS). Additionally, reading data outside the buffer may potentially expose fragments of the device memory contents.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Detailed information regarding the fixed firmware version is available in the SySS advisory: https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-028.txt

Who is affected

Yftech COROS PACE 3 smartwatch with firmware version 3.0808.0 and earlier

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • Yftech Coros Pace 3

    HW
    Yftech
    all versions
  • Yftech Coros Pace 3 Firmware

    OS
    Yftech
    ≤ 3.0808.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2025-32877CRITICAL9.8PL ✓same product

Brak uwierzytelnienia BLE w COROS PACE 3 — atak machine-in-the-middle

CVE-2025-32878CRITICAL9.8PL ✓same product

Brak walidacji certyfikatu TLS w COROS PACE 3 — atak MITM

CVE-2025-32880CRITICAL9.8PL ✓same product

COROS PACE 3 — pobieranie firmware przez niezaszyfrowane HTTP (MitM)

CVE-2025-32879HIGH8.8same product

An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connec...

CVE-2025-48705HIGH7.5same product

An issue was discovered in COROS PACE 3 through 3.0808.0. Due to a NULL pointer dereference vulnerability, sen...