Insecure Firmware Update Mechanism in Deck Mate 2 by Shuffle Master
CVE-2025-34500
Key Information:
- Status
- Vendor
- CVE Published:
- 24 October 2025
Badges
What is CVE-2025-34500?
The Deck Mate 2 firmware update process is compromised due to the acceptance of packages without robust cryptographic signature verification. This vulnerability is exacerbated by the use of a common hard-coded AES key for encryption across devices, combined with a truncated HMAC for integrity checks. Attackers with physical access can exploit this weakness via the unit's USB update port, enabling them to craft or alter firmware packages. This can lead to arbitrary code execution at the root level, jeopardizing the device's integrity and operational processes. Although the primary risk involves access via physical means, potential network exploitation exists if devices are misconfigured. To mitigate these risks, firmware updates have been released to rectify the weaknesses in the update chain, and USB update capabilities have been disabled on vulnerable units.
Affected Version(s)
Deck Mate 2 0
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
