CVE-2025-20702: Airoha Technology Corp AB156X, AB157X, AB158X, AB159X Series, AB1627

High severity, CVSS 8.8. EPSS: 11.5% chance of exploitation in the next 30 days.

In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected products

  • Airoha Technology Corp AB156X, AB157X, AB158X, AB159X Series, AB1627: up to and including v5.5.0; up to and including v3.3.1

Published 2025-08-04. Last modified 2026-06-17.