Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2023-20073Unrestricted File Upload in Cisco Rv340 Firmware

Severity
9.8CRITICALNVD
CNA5.3VulnCheck5.3
EPSS
91.3%
top 0.34%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 5
Latest updateJul 21

Description

A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insufficient authorization enforcement mechanisms in the context of file uploads. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to upload arbitrary

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

🔴Vulnerability Details

3
GHSA
GHSA-w538-44mp-m2cm: A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenti2023-04-05
CVEList
Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Arbitrary File Upload Vulnerability2023-04-05
VulnCheck
Cisco RV Series Routers Unrestricted Upload of File with Dangerous Type2023

💥Exploits & PoCs

1
Nuclei
Cisco VPN Routers - Unauthenticated Arbitrary File Upload

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Cisco RV Series Router form-file-upload Stored Cross Site Scripting Attempt (CVE-2023-20073)2025-07-21

📋Vendor Advisories

1
Cisco
Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Arbitrary File Upload Vulnerability2023-02-01
CVE-2023-20073 — Unrestricted File Upload in Cisco | cvebase