CVE-2025-32880: Yftech Coros Pace 3 Firmware

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN access, the COROS Pace 3 downloads firmware files via HTTP. However, the communication is not encrypted and allows sniffing and machine-in-the-middle attacks.

Affected products

  • Yftech Coros Pace 3 Firmware: up to and including 3.0808.0

Published 2025-06-20. Last modified 2026-06-17.