CVE-2025-54462: Libbiosig Project Libbiosig
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A heap-based buffer overflow vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted .nex file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected products
- Libbiosig Project Libbiosig: before 3.9.1 (fixed in 3.9.1)
Published 2025-08-25. Last modified 2026-06-17.