CVE-2025-34503 Details
Description
Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker with physical access can replace or reflash the EEPROM to run arbitrary code that persists across reboots. Because this design predates modern secure-boot or signed-update mechanisms, affected systems should be physically protected or retired from service. The vendor has not indicated that firmware updates are available for this legacy model.
A vulnerability exists in the Shuffle Master Deck Mate 1 card shuffler, allowing for unauthorized execution of firmware from an external EEPROM. This issue arises because the device does not verify the authenticity or integrity of the firmware, enabling an attacker with physical access to replace or reflash the EEPROM. The modified code can execute arbitrary instructions and persist across reboots. This vulnerability is particularly concerning as it predates modern secure boot and signed update mechanisms, leaving the device open to exploitation. The manufacturer has not provided any firmware updates for this legacy model.
The manufacturer has allegedly released a firmware update addressing the flaws as of October 23, 2025. However, it is unclear if this update is applicable to the Deck Mate 1 model.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 24, 2025CISA-ADP
Assessed Oct 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ioactive.com/wp-content/uploads/2025/05/IOActive-card-shuffler-security.pdf | [email protected] | BundleExploitRemedyTechnical Analysis |
| https://www.vulncheck.com/advisories/shuffle-master-deck-mate-1-unauthenticated-eeprom-firmware-execution | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1326 | Missing Immutable Root of Trust in Hardware | [email protected] |
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Shuffle Master Deck Mate 1 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 24, 2025 | New CVE Received | [email protected] |
Volerion