CVE-2025-20702: High severity Airoha Bluetooth audio SDK vulnerability
Published Aug 4, 2025
·Updated
In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
1 affected component
Airoha Bluetooth audio SDK
Event History
Aug 4, 2025
CVE Published
via MITRE·06:20 AM
Data Sourced
via MITRE·06:20 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Jun 18, 2026
News Published
via BleepingComputer·12:23 PM
News Published
via BleepingComputer·12:26 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-20702?
CVE-2025-20702 has a high severity due to its potential for remote privilege escalation.
2
How do I fix CVE-2025-20702?
To fix CVE-2025-20702, update to the latest version of the Airoha Bluetooth audio SDK that addresses this vulnerability.
3
What is the impact of CVE-2025-20702?
The impact of CVE-2025-20702 includes unauthorized access to the RACE protocol, allowing for remote escalation of privileges.
4
Is user interaction required to exploit CVE-2025-20702?
No, user interaction is not required to exploit CVE-2025-20702.
5
Which products are affected by CVE-2025-20702?
CVE-2025-20702 specifically affects the Airoha Bluetooth audio SDK.