{"id":"CVE-2025-34500","title":"Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key shared across devices, and uses a truncated HMAC for integrity validation","summary":"Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key shared across devices, and uses a truncated HMAC for integrity validation. Attackers wi…","severity":"none","cwe":["CWE-321","CWE-327","CWE-347"],"published":"2025-10-24","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-34500","references":[{"url":"https://www.ioactive.com/wp-content/uploads/2025/05/IOActive-card-shuffler-security.pdf","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/shuffle-master-deck-mate-2-insecure-update-chain","label":"disclosure@vulncheck.com"},{"url":"https://www.wired.com/story/card-shuffler-hack/","label":"disclosure@vulncheck.com"},{"url":"https://www.wired.com/story/how-hacked-card-shufflers-allegedly-enabled-a-mob-fueled-poker-scam-that-rocked-the-nba/","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.0015,"epssPercentile":0.03663,"ingestedAt":"2026-10-08T11:31:27.576Z","slug":"CVE-2025-34500","body":"## Overview\n\nDeck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key shared across devices, and uses a truncated HMAC for integrity validation. Attackers with access to the update interface - typically via the unit's USB update port - can craft or modify firmware packages to execute arbitrary code as root, allowing persistent compromise of the device's integrity and deck randomization process. Physical or on-premises access remains the most likely attack path, though network-exposed or telemetry-enabled deployments could theoretically allow remote exploitation if misconfigured. The vendor confirmed that firmware updates have been issued to correct these update-chain weaknesses and that USB update access has been disabled on affected units.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}