An issue was discovered in COROS PACE 3 through 3.0808.0. Due to a NULL pointer dereference vulnerability, sending a crafted BLE message forces the device to reboot.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://syss.de | third party advisory |
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-027.txt | exploit third party advisory |