CVE-2025-20701

HIGH

Airoha Bluetooth audio SDK - Privilege Escalation

Title source: llm
STIX 2.1

Description

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0340
EPSS Percentile 87.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (2)
Airoha Technology Corp./AB156x, AB157x, AB158x, AB159x series Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier
Airoha Technology Corp./AB156x, AB157x, AB158x, AB159x series Airoha IoT SDK for BT audio v5.5.0 and earlier
Published Aug 04, 2025
Tracked Since Feb 18, 2026