---
id: CVE-2025-34502
title: >-
  Deck Mate 2 lacks a verified secure-boot chain and runtime integrity
  validation for its controller and display modules
summary: >-
  Deck Mate 2 lacks a verified secure-boot chain and runtime integrity
  validation for its controller and display modules. Without cryptographic boot
  verification, an attacker with physical access can modify or replace the
  bootloader, kerne…
severity: none
cwe:
  - CWE-1326
published: '2025-10-24'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34502'
references:
  - url: >-
      https://www.ioactive.com/wp-content/uploads/2025/05/IOActive-card-shuffler-security.pdf
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/shuffle-master-deck-mate-2-missing-secure-boot
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00216
epssPercentile: 0.10822
ingestedAt: '2026-09-30T23:29:32.448Z'
---

## Overview

Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules. Without cryptographic boot verification, an attacker with physical access can modify or replace the bootloader, kernel, or filesystem and gain persistent code execution on reboot. This weakness allows long-term firmware tampering that survives power cycles. The vendor indicates that more recent firmware updates strengthen update-chain integrity and disable physical update ports to mitigate related attack avenues.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
