PT-2025-27364 · Airoha+1 · Airoha Chips+1

·

CVE-2025-20702

·

Published

2025-06-29

·

Updated

2026-06-19

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Airoha Bluetooth audio SDK (affected versions not specified)
Description A lack of authentication in the Custom Protocol of Airoha Technology Bluetooth chips allows unauthorized access to the RACE protocol. This flaw enables a remote attacker to bypass security restrictions and achieve remote escalation of privilege without requiring additional execution privileges or user interaction. This issue can be exploited to gain unauthorized access and perform eavesdropping on affected headphones.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01013
CVE-2025-20702

Affected Products

Airoha Chips
Jabra