CVE-2025-34503CWE-1326CWE-347

Shuffle Master Deck Mate 1 Unauthenticated EEPROM Firmware Execution

High · published October 24, 2025

CVSS v4.0
7.0
EPSS
0%
Percentile
2.2
In the wild
Unconfirmed
What it is

Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker with physical access can replace or reflash the EEPROM to run arbitrary code that persists across reboots. Because this design predates modern secure-boot or signed-update mechanisms, affected systems should be physically protected or retired from service. The vendor has not indicated that firmware updates are available for this legacy model.

The record
Technical detail
CVSS v4.0
7.0 · HIGH
Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00122 · 2.2th percentile
Weaknesses
CWE-1326 · Missing Immutable Root of Trust in Hardware; CWE-347 · Improper Verification of Cryptographic Signature
Published
2025-10-24T23:04Z
EPSS history
Timeline
  • 24 OCT 23:04Z
    Shuffle Master Deck Mate 1 Unauthenticated EEPROM Firmware Execution
    cvelistv5