CVE-2025-20701: High severity Airoha Bluetooth audio SDK vulnerability
Bluetooth. This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
Other sources
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20701?
CVE-2025-20701 is classified as a high-severity vulnerability due to the potential for remote escalation of privilege without user consent.
How do I fix CVE-2025-20701?
To mitigate CVE-2025-20701, users should update to the latest version of the Airoha Bluetooth audio SDK that includes a security patch.
What type of exploitation is possible with CVE-2025-20701?
CVE-2025-20701 allows for exploitation that can lead to the pairing of a Bluetooth audio device without user consent.
Is user interaction required to exploit CVE-2025-20701?
No, user interaction is not needed for the exploitation of CVE-2025-20701, making it particularly concerning.
Which software is affected by CVE-2025-20701?
The vulnerability CVE-2025-20701 specifically affects the Airoha Bluetooth audio SDK.