CNNVD-202510-3399 Information

CNNVD ID

CNNVD-202510-3399

CVE-2025-34500

  • CNNVD Published: 2025-10-24

Description (Chinese)

Light & Wonder Deck Mate是英国Light & Wonder公司的一款自动发牌设备。 Light & Wonder Deck Mate存在安全漏洞,该漏洞源于固件更新机制未验证加密签名并使用硬编码AES密钥,可能导致执行任意代码。

Description (English)

Light & Wonder Deck Mate is an automated distribution device by Light & Wonder, United Kingdom. Light & Wonder Deck Mate has a security loophole, which stems from the fact that the firmware update mechanism does not verify the encrypted signature and uses a hard-coded AES key, which may lead to the execution of any code.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Light & Wonder

Published

2025-10-24

Last Modified

2026-02-24

References

https://www.ioactive.com/wp-content/uploads/2025/05/IOActive-card-shuffler-security.pdf https://www.wired.com/story/how-hacked-card-shufflers-allegedly-enabled-a-mob-fueled-poker-scam-that-rocked-the-nba/ https://www.vulncheck.com/advisories/shuffle-master-deck-mate-2-insecure-update-chain https://www.wired.com/story/card-shuffler-hack/ https://access.redhat.com/security/cve/cve-2025-34500

Share on: