PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-4105 BG-TEK CVE debrief

CVE-2021-4105 is a critical vulnerability (CVSS 9.8) in BG-TEK COSLAT Firewall products that allows remote code inclusion through improper handling of parameters. The vulnerability affects multiple COSLAT Firewall hardware models running firmware versions from 5.24.0.R.20180630 through 5.24.0.R.20210727. The issue was publicly disclosed on 2023-02-24, though the vendor released a critical security update on 2021-07-27 that addresses this vulnerability. Turkish government cybersecurity authorities (USOM and siberguvenlik.gov.tr) have issued advisories regarding this issue. Organizations running affected COSLAT Firewall firmware versions should upgrade to version 5.24.0.R.20210727 or later.

Vendor
BG-TEK
Product
COSLAT Firewall
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2023-02-24
Original CVE updated
2026-05-18
Advisory published
2023-02-24
Advisory updated
2026-05-18

Who should care

Organizations deploying BG-TEK COSLAT Firewall appliances for network perimeter security, particularly in Turkey and regions where these appliances are commonly deployed. Security teams responsible for firewall infrastructure, network administrators managing COSLAT devices, and compliance officers tracking critical vulnerability remediation timelines.

Technical summary

The vulnerability stems from improper handling of parameters (CWE-755) in the COSLAT Firewall firmware, enabling remote attackers to include and execute arbitrary code without authentication. The attack vector is network-based with low complexity, requiring no privileges or user interaction. Affected firmware versions span from June 2018 (5.24.0.R.20180630) to July 2021 (5.24.0.R.20210727). The vendor released a critical security update on July 27, 2021. Multiple hardware platforms are affected including BX5S1D3, BX5S1D4, BX5S1D5, RM1DS1000, RM2DS2000, RM2S200, RM3S300, and RM4S500 models.

Defensive priority

critical

Recommended defensive actions

  • Upgrade COSLAT Firewall firmware to version 5.24.0.R.20210727 or later to remediate the remote code inclusion vulnerability.
  • Verify firmware version on all BG-TEK COSLAT Firewall appliances including models BX5S1D3, BX5S1D4, BX5S1D5, RM1DS1000, RM2DS2000, RM2S200, RM3S300, and RM4S500.
  • If immediate patching is not possible, restrict administrative access to the firewall management interface to trusted internal networks only.
  • Monitor firewall logs for anomalous parameter handling or unexpected code execution attempts.
  • Review vendor security advisories from BG-TEK for additional hardening recommendations.

Evidence notes

Vendor advisory published 2021-07-27; CVE published 2023-02-24; Turkish national CERT advisories issued.

Official resources

public