CVE-2025-20701: exploitation status and patch state

CVE-2025-20701 · CVSS 8.8 HIGH · EPSS 7%

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Is CVE-2025-20701 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2025-20701

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.