Shuffle Master Deck Mate 1 Unauthenticated EEPROM Firmware Execution
Vulnerability Description
Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker with physical access can replace or reflash the EEPROM to run arbitrary code that persists across reboots. Because this design predates modern secure-boot or signed-update mechanisms, affected systems should be physically protected or retired from service. The vendor has not indicated that firmware updates are available for this legacy model.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34503
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Joseph Tartaro of IOActive
- Enrique Nissim of IOActive
- Ethan Shackelford of IOActive
References
More from Light & Wonder, Inc. / SHFL Entertainment, Inc. / Shuffle Master, Inc.
View All →Affected Vendor
Light & Wonder, Inc. / SHFL Entertainment, Inc. / Shuffle Master, Inc.
View all reports →