CVE Database
/

CVE-2025-34500

Back to search

CVE-2025-34500

Published: Oct 24, 2025

Modified: Oct 27, 2025

PUBLISHED

Description

Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key shared across devices, and uses a truncated HMAC for integrity validation. Attackers with access to the update interface - typically via the unit's USB update port - can craft or modify firmware packages to execute arbitrary code as root, allowing persistent compromise of the device's integrity and deck randomization process. Physical or on-premises access remains the most likely attack path, though network-exposed or telemetry-enabled deployments could theoretically allow remote exploitation if misconfigured. The vendor confirmed that firmware updates have been issued to correct these update-chain weaknesses and that USB update access has been disabled on affected units.

VendorProductVersions

Light & Wonder, Inc. / SHFL Entertainment, Inc. / Shuffle Master, Inc.

Deck Mate 2

affected
0 - < all known versions prior to 2025-10-23

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2025-34500 - Security Vulnerability | QwikSec