CVE-2025-20701

8.8

Airoha · Bluetooth audio SDK

An authorization bypass in the Airoha Bluetooth audio SDK allows unauthenticated attackers to pair with Bluetooth devices without user consent, enabling potential eavesdropping and privilege escalation.

Executive summary

A critical authorization bypass in the Airoha Bluetooth audio SDK allows unauthorized pairing with various consumer audio devices, facilitating eavesdropping and remote control.

Vulnerability

This is an unauthenticated authorization bypass vulnerability where an attacker within Bluetooth range can force a pairing request without user interaction. The flaw leverages the SDK's pairing logic to bypass consent mechanisms, allowing attackers to intercept communications or impersonate legitimate devices.

Business impact

The CVSS score of 8.8 reflects the high risk posed by this vulnerability, as it affects a wide range of consumer electronics used in both personal and professional environments. Successful exploitation allows for unauthorized eavesdropping, firmware extraction, and potential man-in-the-middle attacks, leading to significant privacy loss and potential exposure of sensitive organizational communications.

Remediation

Immediate Action: Update affected hardware firmware to the latest versions provided by the manufacturer, such as Beats Firmware 1B211, or apply patches provided by the specific device vendor.

Proactive Monitoring: Monitor Bluetooth connectivity logs for unexpected pairing attempts or connections from unrecognized device MAC addresses.

Compensating Controls: Disable Bluetooth connectivity on affected devices when not in use, particularly in public or untrusted environments, to minimize the attack surface.

Exploitation status

Public Exploit Available: true

Analyst recommendation

Given the availability of a public exploit and the wide deployment of affected hardware, this vulnerability poses a severe risk. Organizations should identify all impacted Bluetooth audio devices in their inventory and prioritize the deployment of vendor-supplied firmware updates immediately to prevent unauthorized access and eavesdropping.

More Airoha CVEs