---
id: CVE-2025-34500
title: >-
  Deck Mate 2's firmware update mechanism accepts packages without cryptographic
  signature verification, encrypts them with a single hard-coded AES key shared
  across devices, and uses a truncated HMAC for integrity validation
summary: >-
  Deck Mate 2's firmware update mechanism accepts packages without cryptographic
  signature verification, encrypts them with a single hard-coded AES key shared
  across devices, and uses a truncated HMAC for integrity validation. Attackers
  wi…
severity: none
cwe:
  - CWE-321
  - CWE-327
  - CWE-347
published: '2025-10-24'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34500'
references:
  - url: >-
      https://www.ioactive.com/wp-content/uploads/2025/05/IOActive-card-shuffler-security.pdf
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/shuffle-master-deck-mate-2-insecure-update-chain
    label: disclosure@vulncheck.com
  - url: 'https://www.wired.com/story/card-shuffler-hack/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.wired.com/story/how-hacked-card-shufflers-allegedly-enabled-a-mob-fueled-poker-scam-that-rocked-the-nba/
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.0015
epssPercentile: 0.03663
ingestedAt: '2026-10-08T11:31:27.576Z'
---

## Overview

Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key shared across devices, and uses a truncated HMAC for integrity validation. Attackers with access to the update interface - typically via the unit's USB update port - can craft or modify firmware packages to execute arbitrary code as root, allowing persistent compromise of the device's integrity and deck randomization process. Physical or on-premises access remains the most likely attack path, though network-exposed or telemetry-enabled deployments could theoretically allow remote exploitation if misconfigured. The vendor confirmed that firmware updates have been issued to correct these update-chain weaknesses and that USB update access has been disabled on affected units.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
