# CVE-2025-58742

## Summary

- **CVE ID:** CVE-2025-58742
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-522, CWE-923
- **Published:** Jan 20, 2026
- **Last Modified:** Mar 13, 2026

## Description

Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Capture on Windows allows Adversary in the Middle (AiTM) by modifying the 'Server' field to redirect client authentication.This issue affects ImageDirector Capture: from 7.0.9 before 7.6.3.25808.

## Affected Products

- Milner — ImageDirector Capture (7.0.9)

## References

- [CNA](https://sra.io/advisories)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._