CVE Database
/

CVE-2025-20700

Back to search

CVE-2025-20700

Published: Aug 4, 2025

Modified: Feb 26, 2026

PUBLISHED

Description

In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT service. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

VendorProductVersions

Airoha Technology Corp.

AB156x, AB157x, AB158x, AB159x series, AB1627

affected
Airoha IoT SDK for BT audio v5.5.0 and earlier
affected
Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now