In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.airoha.com/product-security-bulletin/2025 |
![]() ![]() |
History
Tue, 05 Aug 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Airoha
Airoha ab156x Airoha ab157x Airoha ab158x Airoha ab159x Airoha ab1627 Airoha bluetooth Audio Sdk |
|
Vendors & Products |
Airoha
Airoha ab156x Airoha ab157x Airoha ab158x Airoha ab159x Airoha ab1627 Airoha bluetooth Audio Sdk |
Mon, 04 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 04 Aug 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
Weaknesses | CWE-306 | |
References |
|

Status: PUBLISHED
Assigner: MediaTek
Published:
Updated: 2025-08-05T03:56:11.216Z
Reserved: 2024-11-01T01:21:50.382Z
Link: CVE-2025-20702

Updated: 2025-08-04T13:46:58.016Z

Status : Awaiting Analysis
Published: 2025-08-04T07:15:28.190
Modified: 2025-08-04T15:06:15.833
Link: CVE-2025-20702

No data.