PT-2025-27364 · Airoha+1 · Airoha Chips+1

Dennis Heinze

+2

·

Published

2025-06-29

·

Updated

2026-01-03

·

CVE-2025-20702

CVSS v3.1
8.8
VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Airoha Bluetooth audio SDK (affected versions not specified)
Description The Airoha Bluetooth audio SDK contains a flaw involving unauthorized access to the RACE protocol. This access could allow for remote escalation of privilege without requiring additional execution privileges, and does not require user interaction for exploitation. Reports indicate that devices utilizing Airoha chips may be susceptible to unauthorized access and eavesdropping due to a lack of authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2026-01013
CVE-2025-20702

Affected Products

Airoha Chips
Jabra