PatchSiren cyber security CVE debrief
CVE-2021-4105 BG-TEK CVE debrief
CVE-2021-4105 is a critical vulnerability (CVSS 9.8) in BG-TEK COSLAT Firewall products that allows remote code inclusion through improper handling of parameters. The vulnerability affects multiple COSLAT Firewall hardware models running firmware versions from 5.24.0.R.20180630 through 5.24.0.R.20210727. The issue was publicly disclosed on 2023-02-24, though the vendor released a critical security update on 2021-07-27 that addresses this vulnerability. Turkish government cybersecurity authorities (USOM and siberguvenlik.gov.tr) have issued advisories regarding this issue. Organizations running affected COSLAT Firewall firmware versions should upgrade to version 5.24.0.R.20210727 or later.
- Vendor
- BG-TEK
- Product
- COSLAT Firewall
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-02-24
- Original CVE updated
- 2026-05-18
- Advisory published
- 2023-02-24
- Advisory updated
- 2026-05-18
Who should care
Organizations deploying BG-TEK COSLAT Firewall appliances for network perimeter security, particularly in Turkey and regions where these appliances are commonly deployed. Security teams responsible for firewall infrastructure, network administrators managing COSLAT devices, and compliance officers tracking critical vulnerability remediation timelines.
Technical summary
The vulnerability stems from improper handling of parameters (CWE-755) in the COSLAT Firewall firmware, enabling remote attackers to include and execute arbitrary code without authentication. The attack vector is network-based with low complexity, requiring no privileges or user interaction. Affected firmware versions span from June 2018 (5.24.0.R.20180630) to July 2021 (5.24.0.R.20210727). The vendor released a critical security update on July 27, 2021. Multiple hardware platforms are affected including BX5S1D3, BX5S1D4, BX5S1D5, RM1DS1000, RM2DS2000, RM2S200, RM3S300, and RM4S500 models.
Defensive priority
critical
Recommended defensive actions
- Upgrade COSLAT Firewall firmware to version 5.24.0.R.20210727 or later to remediate the remote code inclusion vulnerability.
- Verify firmware version on all BG-TEK COSLAT Firewall appliances including models BX5S1D3, BX5S1D4, BX5S1D5, RM1DS1000, RM2DS2000, RM2S200, RM3S300, and RM4S500.
- If immediate patching is not possible, restrict administrative access to the firewall management interface to trusted internal networks only.
- Monitor firewall logs for anomalous parameter handling or unexpected code execution attempts.
- Review vendor security advisories from BG-TEK for additional hardening recommendations.
Evidence notes
Vendor advisory published 2021-07-27; CVE published 2023-02-24; Turkish national CERT advisories issued.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-4105 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-4105
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-4105 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-4105
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0108
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-23-0108
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.