In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.airoha.com/product-security-bulletin/2025 |
![]() ![]() |
History
Tue, 05 Aug 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Airoha
Airoha ab156x Airoha ab157x Airoha ab158x Airoha ab159x |
|
Vendors & Products |
Airoha
Airoha ab156x Airoha ab157x Airoha ab158x Airoha ab159x |
Mon, 04 Aug 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 04 Aug 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
Weaknesses | CWE-863 | |
References |
|

Status: PUBLISHED
Assigner: MediaTek
Published: 2025-08-04T06:20:32.057Z
Updated: 2025-08-05T03:56:10.136Z
Reserved: 2024-11-01T01:21:50.382Z
Link: CVE-2025-20701

Updated: 2025-08-04T20:37:47.873Z

Status : Awaiting Analysis
Published: 2025-08-04T07:15:28.027
Modified: 2025-08-04T21:15:29.897
Link: CVE-2025-20701

No data.