CVE-2025-20702

HIGH

Airoha Bluetooth audio SDK - Privilege Escalation

Title source: llm
STIX 2.1

Description

In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0396
EPSS Percentile 89.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (2)
Airoha Technology Corp./AB156x, AB157x, AB158x, AB159x series, AB1627 Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier
Airoha Technology Corp./AB156x, AB157x, AB158x, AB159x series, AB1627 Airoha IoT SDK for BT audio v5.5.0 and earlier
Published Aug 04, 2025
Tracked Since Feb 18, 2026