Bluetooth Audio SDK Vulnerability in Airoha Products
CVE-2025-20701

8.8HIGH

What is CVE-2025-20701?

A flaw exists in the Airoha Bluetooth audio SDK that potentially allows attackers to pair Bluetooth audio devices without the explicit consent of the user. This vulnerability can lead to unauthorized access and privilege escalation without requiring any user interaction, thereby posing a significant risk to the security and privacy of users. A detailed security bulletin is available for further insights.

Affected Version(s)

AB156x, AB157x, AB158x, AB159x series Airoha IoT SDK for BT audio v5.5.0 and earlier

AB156x, AB157x, AB158x, AB159x series Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.