---
id: CVE-2025-11145
title: >-
  Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized
  Actor, Exposure of Private Personal Information to an Unauthorized Actor
  vulnerability in CBK Soft Software Hardware Electronic Computer Systems
  Industry and Tr…
summary: >-
  Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized
  Actor, Exposure of Private Personal Information to an Unauthorized Actor
  vulnerability in CBK Soft Software Hardware Electronic Computer Systems
  Industry and Tr…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
  - CWE-203
  - CWE-359
published: '2025-10-24'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11145'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0361'
    label: iletisim@usom.gov.tr
  - url: 'https://www.usom.gov.tr/bildirim/tr-25-0361'
    label: iletisim@usom.gov.tr
tags:
  - nvd
epss: 0.00346
epssPercentile: 0.25995
ingestedAt: '2026-10-08T11:31:27.574Z'
---

## Overview

Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware Electronic Computer Systems Industry and Trade Inc. EnVision allows Account Footprinting.

This issue affects enVision: before 250566.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
