CVE-2025-34502CWE-1326

Shuffle Master Deck Mate 2 Missing Secure Boot

High · published October 24, 2025

CVSS v4.0
7.0
EPSS
0%
Percentile
10.0
In the wild
Unconfirmed
What it is

Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules. Without cryptographic boot verification, an attacker with physical access can modify or replace the bootloader, kernel, or filesystem and gain persistent code execution on reboot. This weakness allows long-term firmware tampering that survives power cycles. The vendor indicates that more recent firmware updates strengthen update-chain integrity and disable physical update ports to mitigate related attack avenues.

The record
Technical detail
CVSS v4.0
7.0 · HIGH
Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00201 · 10.0th percentile
Weakness
CWE-1326 · Missing Immutable Root of Trust in Hardware
Published
2025-10-24T23:04Z
EPSS history
Timeline
  • 24 OCT 23:04Z
    Shuffle Master Deck Mate 2 Missing Secure Boot
    cvelistv5