PT-2025-27364 · Airoha +1 · Airoha Chips +1
Dennis Heinze
+2
·
Published
2025-06-29
·
Updated
2025-08-09
·
CVE-2025-20702
CVSS v3.1
8.8
8.8
High
Base vector | Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
Airoha Bluetooth audio SDK (affected versions not specified)
**Description:**
In the Airoha Bluetooth audio SDK, unauthorized access to the RACE protocol is possible. This could lead to remote escalation of privilege without requiring additional execution privileges, and does not require user interaction for exploitation. Reports indicate that devices utilizing Airoha chips may be affected, potentially allowing unauthorized access and eavesdropping.
**Recommendations:**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Missing Authentication
Weakness Enumeration
Related Identifiers
CVE-2025-20702
Affected Products
Airoha Chips
Jabra
References · 19
- https://nvd.nist.gov/vuln/detail/CVE-2025-20702 · Security Note
- https://twitter.com/cybersecur80472/status/1943231961767571869 · Twitter Post
- https://twitter.com/NumeroUnoHacker/status/1942841734041592093 · Twitter Post
- https://twitter.com/cracbot/status/1954135610978869255 · Twitter Post
- https://twitter.com/CVEnew/status/1952257513207869573 · Twitter Post
- https://t.me/cveNotify/130731 · Telegram Post
- https://twitter.com/D_Hackz/status/1943278782644916494 · Twitter Post
- https://twitter.com/infiltr08/status/1941894497002041745 · Twitter Post
- https://twitter.com/nathy_hackers/status/1943183077477618153 · Twitter Post
- https://airoha.com/product-security-bulletin/2025 · Note
- https://twitter.com/Strivehawk/status/1940112534088163832 · Twitter Post
- https://t.me/purp_sec/824 · Telegram Post
- https://twitter.com/SacreedTol/status/1942769440338161815 · Twitter Post
- https://twitter.com/cyberuncrack/status/1942802517248680341 · Twitter Post
- https://twitter.com/mountainman1977/status/1939232833546944662 · Twitter Post