PT-2025-27364 · Airoha +1 · Airoha Chips +1

Dennis Heinze

+2

·

Published

2025-06-29

·

Updated

2025-08-09

·

CVE-2025-20702

CVSS v3.1
8.8
VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

Airoha Bluetooth audio SDK (affected versions not specified)

**Description:**

In the Airoha Bluetooth audio SDK, unauthorized access to the RACE protocol is possible. This could lead to remote escalation of privilege without requiring additional execution privileges, and does not require user interaction for exploitation. Reports indicate that devices utilizing Airoha chips may be affected, potentially allowing unauthorized access and eavesdropping.

**Recommendations:**

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-20702

Affected Products

Airoha Chips
Jabra