CVE-2025-20701: exploitation status and patch state
CVE-2025-20701 · CVSS 8.8 HIGH · EPSS 7%
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Is CVE-2025-20701 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 7%.
Public exploit code: none found in monitored sources.