news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2025-20701

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
8.8 High
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Risk score
70.4
Published
2025-08-04
Status
Deferred

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Weaknesses

CWE-863

Coverage 3

Advisories and references