CVE-2023-24256: Nio Aspen

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue in the com.nextev.datastatistic component of NIO EC6 Aspen before v3.3.0 allows attackers to escalate privileges via path traversal.

Affected products

  • Nio Aspen: before 3.3.0 (fixed in 3.3.0)

Published 2023-07-06. Last modified 2026-06-17.