๐Ÿ” CVE Alert

CVE-2025-34501

UNKNOWN 0.0

Shuffle Master Deck Mate 2 Hard-coded Credentials & Exposed Services

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple management services (SSH, HTTP, Telnet, SMB, X11) are enabled by default. If an attacker can reach these interfaces - most often through local or near-local access such as connecting to the USB or Ethernet ports beneath the table - the built-in credentials permit administrative login and full control of the system. Once authenticated, an attacker can access firmware utilities, modify controller software, and establish persistent compromise. Remote attack paths via network, cellular, or telemetry links may exist in specific configurations but generally require additional capabilities or operator error. The vendor reports that USB access has been disabled in current firmware builds.

CWE CWE-798
Vendor light & wonder, inc. / shfl entertainment, inc. / shuffle master, inc.
Product deck mate 2
Published Nov 3, 2025
Last Updated Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for light & wonder, inc. / shfl entertainment, inc. / shuffle master, inc. deck mate 2

Be the first to know when new unknown vulnerabilities affecting light & wonder, inc. / shfl entertainment, inc. / shuffle master, inc. deck mate 2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Light & Wonder, Inc. / SHFL Entertainment, Inc. / Shuffle Master, Inc. / Deck Mate 2
0 < all known versions prior to 2025-10-23

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
ioactive.com: https://www.ioactive.com/wp-content/uploads/2025/05/IOActive-card-shuffler-security.pdf vulncheck.com: https://www.vulncheck.com/advisories/shuffle-master-deck-mate-2-hard-coded-credentials-and-exposed-services

Credits

Joseph Tartaro of IOActive Enrique Nissim of IOActive Ethan Shackelford of IOActive