CVE-2025-20701
Summary
| CVE | CVE-2025-20701 |
|---|---|
| State | PUBLISHED |
| Assigner | MediaTek |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-08-04 07:15:28 UTC |
| Updated | 2026-06-21 09:16:24 UTC |
| Description | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from ADP
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-863 | CWE-863 CWE-863 Incorrect Authorization
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 8.8 | HIGH | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Airoha Technology Corp. | AB156x AB157x AB158x AB159x Series | affected Airoha IoT SDK for BT audio v5.5.0 and earlier | Not specified |
| CNA | Airoha Technology Corp. | AB156x AB157x AB158x AB159x Series | affected Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.airoha.com/product-security-bulletin/2025 | [email protected] | www.airoha.com | |
| seclists.org/fulldisclosure/2026/Jun/18 | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.