---
id: CVE-2025-20701
title: >-
  In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth
  audio device without user consent
summary: >-
  In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth
  audio device without user consent. This could lead to remote escalation of
  privilege with no additional execution privileges needed. User interaction is
  not nee…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-863
vendor: Airoha Technology Corp.
product: 'AB156x, AB157x, AB158x, AB159x series'
affected:
  - >-
    ab156x_ab157x_ab158x_ab159x_series Airoha IoT SDK for BT audio v5.5.0 and
    earlier
  - >-
    ab156x_ab157x_ab158x_ab159x_series Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1
    and earlier
published: '2025-08-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T16:17:48.883'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-20701'
references:
  - url: 'https://www.airoha.com/product-security-bulletin/2025'
    label: security@mediatek.com
  - url: 'http://seclists.org/fulldisclosure/2026/Aug/7'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2026/Jun/18'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/859658'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-08-05T03:56:10.880579Z'
epss: 0.0867
epssPercentile: 0.94886
ingestedAt: '2026-08-06T23:06:29.093Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/x0jac0b0x/skullcandy-dime3-cve-2025-20701'
  checkedAt: '2026-09-24T07:52:52.946Z'
exploitAvailable: true
---

## Overview

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
