CVE-2025-20701 describes a critical vulnerability in the Airoha Bluetooth audio SDK that allows for unauthorized Bluetooth device pairing without user consent. This flaw can lead to remote escalation of privilege, requiring no user interaction or additional execution privileges for successful exploitation. With a CVSS score of 8.8 (High), the vulnerability presents a significant risk due to its low attack complexity, network-based attack vector, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered notable community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Airoha Technology Corp. | AB156x, AB157x, AB158x, AB159x Series | Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier, Airoha IoT SDK for BT audio v5.5.0 and earlierCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.