CVE-2025-20702 is an authorization weakness in the Airoha Bluetooth audio SDK involving insufficient restriction of privileged functionality exposed through the proprietary RACE protocol. The protocol exposes internal management and debug-style capabilities that can be reached remotely over Bluetooth on affected devices. Available operations reportedly include retrieving device information, obtaining the Bluetooth Classic address, reading flash memory, and performing arbitrary read and write operations on RAM. Because access to these capabilities is not adequately restricted, a nearby attacker can gain unauthorized access to sensitive device internals and management functions without user interaction. In practical attack chains, this weakness can be combined with other Airoha Bluetooth authentication flaws to facilitate broader compromise of the audio device and its trusted relationship with a paired phone.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A flaw that enables a nearby attacker to evade security controls and access internal management settings on the earbuds, used in chaining with other Bluetooth issues.
An Airoha SoC vulnerability that, when chained with related flaws, could help attackers intercept Bluetooth connections and interact with a connected smartphone.
A vulnerability that, when chained with CVE-2025-20701 and CVE-2025-20700, could enable hijacking of the Bluetooth Hands-Free Profile to issue commands to a phone.
A vulnerability affecting the same Airoha Bluetooth component that can be chained with CVE-2025-20701 and CVE-2025-20700 to hijack the connection between a phone and a paired Bluetooth audio device and issue HFP commands to the phone.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.