Firmware Vulnerability in Deck Mate 1 by Shuffle Master
CVE-2025-34503

7HIGH

Key Information:

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2025-34503?

Deck Mate 1 is susceptible to a critical firmware vulnerability that allows attackers with physical access to manipulate EEPROM. By replacing or reflashing the EEPROM, they can execute arbitrary code that remains active even after system reboots. This security flaw arises from the absence of security measures such as secure-boot and signed updates, necessitating physical protection for affected systems. No firmware updates have been provided for this outdated model, further exposing it to potential exploitation.

Affected Version(s)

Deck Mate 1 0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joseph Tartaro of IOActive
Enrique Nissim of IOActive
Ethan Shackelford of IOActive
.