Home

Description

Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows decryption of document archive files using credentials decrypted with hard-coded application encryption key. This issue affects ImageDirector Capture: from 7.0.9.0 before 7.6.3.25808.

PUBLISHED Reserved 2025-09-04 | Published 2026-01-20 | Updated 2026-01-21 | Assigner SRA




MEDIUM: 6.9CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-1392 Use of Default Credentials

CWE-798 Use of Hard-coded Credentials

Product status

Default status
unaffected

7.0.9.0 (semver) before 7.6.3.25808
affected

Credits

Asa Reynolds (SRA) finder

Rick Console (SRA) finder

References

sra.io/advisories

cve.org (CVE-2025-58744)

nvd.nist.gov (CVE-2025-58744)

Download JSON