In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT service. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.airoha.com/product-security-bulletin/2025 |
![]() ![]() |
History
Tue, 05 Aug 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Airoha
Airoha ab156x Airoha ab157x Airoha ab158x Airoha ab159x Airoha ab1627 Airoha bluetooth Audio Sdk |
|
Vendors & Products |
Airoha
Airoha ab156x Airoha ab157x Airoha ab158x Airoha ab159x Airoha ab1627 Airoha bluetooth Audio Sdk |
Mon, 04 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 04 Aug 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT service. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
Weaknesses | CWE-306 | |
References |
|

Status: PUBLISHED
Assigner: MediaTek
Published:
Updated: 2025-08-05T03:56:09.060Z
Reserved: 2024-11-01T01:21:50.382Z
Link: CVE-2025-20700

Updated: 2025-08-04T13:19:50.001Z

Status : Awaiting Analysis
Published: 2025-08-04T07:15:26.740
Modified: 2025-08-04T15:06:15.833
Link: CVE-2025-20700

No data.