# CVE-2025-20701

## Summary

- **CVE ID:** CVE-2025-20701
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-863
- **Published:** Aug 4, 2025
- **Last Modified:** Sep 8, 2026

## Description

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected Products

- Airoha Technology Corp. — AB156x, AB157x, AB158x, AB159x series (Airoha IoT SDK for BT audio v5.5.0 and earlier)
- Airoha Technology Corp. — AB156x, AB157x, AB158x, AB159x series (Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier)

## References

- [CNA](https://www.airoha.com/product-security-bulletin/2025)
- [CVE](http://seclists.org/fulldisclosure/2026/Jun/18)
- [CVE](http://seclists.org/fulldisclosure/2026/Aug/7)
- [CVE](https://www.kb.cert.org/vuls/id/859658)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 8.67%
- **EPSS Percentile:** 94.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._