CVE-2025-34503 - CVE House
Back to Database
Status published High CVE-2025-34503

Shuffle Master Deck Mate 1 Unauthenticated EEPROM Firmware Execution

Vulnerability Description

Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker with physical access can replace or reflash the EEPROM to run arbitrary code that persists across reboots. Because this design predates modern secure-boot or signed-update mechanisms, affected systems should be physically protected or retired from service. The vendor has not indicated that firmware updates are available for this legacy model.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34503

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Joseph Tartaro of IOActive
  • Enrique Nissim of IOActive
  • Ethan Shackelford of IOActive

Affected Vendor

Light & Wonder, Inc. / SHFL Entertainment, Inc. / Shuffle Master, Inc.

View all reports →

Affected Software

Deck Mate 1
Vulnerable Versions:
0

Timeline

Official Publish: October 24th, 2025
Last Modified: October 27th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)