ZeroHour
Story · 1 source · 1 articlefirst updated ()1

Skullcandy Dime 3 earbuds accept silent Bluetooth pairings via Airoha SDK flaw CVE-2025-20701, exposing audio and microphone; fixed in firmware 1.0.0.30 but existing units…

mediumVulnerabilityimportance 45CVE-2025-20701
What's new: Since the previous summary (2026-09-10), a fourth source, Cyber Security News (2026-09-11), was added. It corroborates all previously reported facts — the affected model S2DCW on firmware 1.0.0.28, the NoInputNoOutput unauthenticated pairing, automatic reconnection of bonded attacker devices, A2DP hijacking, HFP/HSP microphone capture, and the lack of an in-app update path — and adds no new…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

CERT/CC's VU#859658 describes CVE-2025-20701, a missing-authentication flaw in the Airoha Bluetooth audio SDK, that lets in-range attackers who know the device address silently pair with Skullcandy Dime 3 (model S2DCW) earbuds on firmware 1.0.0.28, hijack…

CERT/CC vulnerability note VU#859658 (2026-09-08), BleepingComputer (2026-09-09), GBHackers (2026-09-10), and Cyber Security News (2026-09-11) all report CVE-2025-20701, a missing-authentication vulnerability in Airoha Bluetooth audio SDK implementations that BleepingComputer characterizes as a high-severity flaw. It affects the Skullcandy Dime 3 wireless earbuds (model S2DCW) running firmware 1.0.0.28, which accept Bluetooth Classic BR/EDR pairing requests from unknown devices without the owner activating pairing mode or providing any confirmation. A direct pairing request with no PIN, passkey, or physical confirmation completes via the NoInputNoOutput configuration, adding the attacker's device as trusted. Per GBHackers, the attacker needs only Bluetooth range and knowledge of the device address; once bonded, the attacker's device can reconnect automatically whenever it is in range. An attacker in radio range can then hijack the A2DP audio session, disrupt the owner's active audio, access the Hands-Free/Headset (HFP/HSP) profiles, and capture live microphone audio. Per BleepingComputer, the flaw was discovered by ERNW researchers and affects earbud and headphone products from multiple vendors; Apple patched the same SDK flaw for Beats Studio Buds in June. Skullcandy fixed the issue in firmware 1.0.0.30, which CERT/CC says contains the effective patch (Cyber Security News characterizes it as 'reportedly' fixing the flaw), but the Dime 3 does not support firmware updates through the Skullcandy mobile app, so customers have no consumer-accessible way to update existing units, which remain unpatchable. All four sources agree on the CVE, affected model and firmware versions, attack mechanics, impact, the 1.0.0.30 fix, and the lack of an update path; no disagreements were reported.

  • CVE-2025-20701 is a missing-authentication vulnerability in Airoha Bluetooth audio SDK implementations, tracked by CERT/CC as VU#859658; BleepingComputer characterizes it as high severity.
  • Affected product: Skullcandy Dime 3 wireless earbuds, model S2DCW, running firmware 1.0.0.28.
  • Unauthenticated Bluetooth Classic BR/EDR pairing completes via the NoInputNoOutput configuration without pairing mode, PIN, passkey, or user confirmation, adding the attacker's device as trusted.
  • Per GBHackers, attackers need only Bluetooth range and knowledge of the device address; once bonded, the attacker's device can reconnect automatically whenever it is in range.
  • Impact: hijacking of the A2DP audio session, disruption of the owner's active audio, and Hands-Free/Headset (HFP/HSP) profile access enabling capture of live microphone audio.
  • Fix: firmware 1.0.0.30 — CERT/CC says it contains the effective patch; Cyber Security News says it 'reportedly' fixes the flaw — but the Dime 3 does not support app-based firmware updates, leaving existing units without a…
  • Per BleepingComputer, ERNW researchers discovered the flaw, which affects earbud and headphone products from multiple vendors; Apple patched the same SDK flaw for Beats Studio Buds in June.
  • Sources: CERT/CC (2026-09-08), BleepingComputer (2026-09-09), GBHackers (2026-09-10), and Cyber Security News (2026-09-11); all agree on the CVE, affected versions, attack mechanics, impact, the 1.0.0.30 fix, and the lack of an update path.

Coverage timeline

  1. · 7d ago
    CERT/CC Vulnerability Notes· 24
    VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability

    Skullcandy Dime 3 earbuds (CVE-2025-20701) accept Bluetooth pairings without owner consent, letting in-range attackers hijack audio or capture microphone; no firmware update path exists.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20701
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent.

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

NVD description · AI analysis pending
8.89% PoC