Security Flaw in Deck Mate 2 by Shuffle Master
CVE-2025-34502

7HIGH

What is CVE-2025-34502?

Deck Mate 2 suffers from a boot security vulnerability due to the absence of a verified secure-boot chain and runtime integrity validation. This flaw enables an attacker with physical access to alter or replace the bootloader, kernel, or filesystem. Such alterations can lead to persistent code execution across reboots, posing significant risks for long-term firmware tampering. The vendor has noted that subsequent firmware updates enhance the integrity of the update chain and disable physical update ports to reduce potential exploitation avenues.

Affected Version(s)

Deck Mate 2 0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joseph Tartaro of IOActive
Enrique Nissim of IOActive
Ethan Shackelford of IOActive
.