Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-32876

EPSS 0.08% · P24
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-32876

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure Connections and instead enforces BLE Legacy Pairing. In BLE Legacy Pairing, the Short-Term Key (STK) can be easily guessed. This requires knowledge of the Temporary Key (TK), which, in the case of the COROS Pace 3, is set to 0 due to the Just Works pairing method. An attacker within Bluetooth range can therefore perform sniffing attacks, allowing eavesdropping on the communication.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
COROS PACE 3 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Bluetooth等都是蓝牙特别兴趣小组(SIG)标准组织的产品。Bluetooth是一种短距离无线技术标准,Cafe Bazaar hod等都是(Cafe Bazaar)开源的产品。hod是一个库。roc req等都是(roc)个人开发者的产品。req是一个使用 Black Magic 的简单 Go HTTP 客户端。 COROS PACE 3 3.0808.0及之前版本存在安全漏洞,该漏洞源于BLE实现仅支持旧版配对,可能导致通信窃听。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2025-32876

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-32876

登录查看更多情报信息。

Same Patch Batch · n/a · 2025-06-20 · 15 CVEs total

CVE-2025-63354.7 MEDIUMDedeCMS Template dedetag.class.php command injection
CVE-2025-48705COROS PACE 3 安全漏洞
CVE-2025-48706COROS PACE 3 安全漏洞
CVE-2025-44203Hoteldruid 安全漏洞
CVE-2025-44635H3C多款产品 安全漏洞
CVE-2025-32879COROS PACE 3 安全漏洞
CVE-2025-32880COROS PACE 3 安全漏洞
CVE-2025-32877COROS PACE 3 安全漏洞
CVE-2025-32875COROS application 安全漏洞
CVE-2025-32878COROS PACE 3 安全漏洞
CVE-2025-46179CloudClassroom-PHP-Project 安全漏洞
CVE-2025-46158Redox C Library 安全漏洞
CVE-2025-45331Brplot v420.69.1 安全漏洞
CVE-2025-45890novel-plus 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-32876

No comments yet


Leave a comment