CVE-2025-20700
As of 2026-02-26, CVE-2025-20700 is a CVSS 8.8 (HIGH-severity) vulnerability. EPSS exploitation probability 6.2%. Threadlinqs Intelligence tracks 1 threat exploiting it.
Last updated: 2026-02-26
In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT service. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS v3 vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-306
Threats tracking this CVE
References
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.