CVE-2025-34500
Shuffle Master Deck Mate 2 Insecure Update Chain
Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key shared across devices, and uses a truncated HMAC for integrity validation. Attackers with access to the update interface - typically via the unit's USB update port - can craft or modify firmware packages to execute arbitrary code as root, allowing persistent compromise of the device's integrity and deck randomization process. Physical or on-premises access remains the most likely attack path, though network-exposed or telemetry-enabled deployments could theoretically allow remote exploitation if misconfigured. The vendor confirmed that firmware updates have been issued to correct these update-chain weaknesses and that USB update access has been disabled on affected units.
| CWE | CWE-321 CWE-327 CWE-347 |
| Vendor | light & wonder, inc. / shfl entertainment, inc. / shuffle master, inc. |
| Product | deck mate 2 |
| Published | Oct 24, 2025 |
| Last Updated | Jul 28, 2026 |
Get instant alerts for light & wonder, inc. / shfl entertainment, inc. / shuffle master, inc. deck mate 2
Be the first to know when new unknown vulnerabilities affecting light & wonder, inc. / shfl entertainment, inc. / shuffle master, inc. deck mate 2 are published โ delivered to Slack, Telegram or Discord.