Junglewise Threat Intelligence

CVE-2021-4477: Hirschmann HiLCOS firewall bypass in IPv6 IPsec deployments

CVE-2021-4477 · Severity: critical · CVSS 9.1 · Published 2026-04-03

Vendors: Hirschmann.

Executive brief

Hirschmann industrial wireless access points and routers are affected by a security flaw that allows unauthorized network traffic to bypass the device's firewall. This occurs specifically when using IPv6 VPN connections, potentially allowing an attacker to access protected internal network resources that should be blocked. This could lead to unauthorized data access or the ability to compromise other systems on the corporate or industrial network.

Technical details

A vulnerability in the firewall policy enforcement of Hirschmann HiLCOS (OpenBAT and BAT450) allows for improper access control (CWE-284) in IPv6 IPsec deployments. The flaw is triggered when an attacker establishes an IPv6 IPsec connection (using either IKEv1 or IKEv2) while simultaneously utilizing an IPv6 internet connection. This specific configuration causes the device to fail to apply configured firewall rules to the VPN traffic, allowing it to bypass security policies. The vulnerability is reachable over the network without authentication. A fix is available in version 10.12-RU2 and later.

Affected products

  • Hirschmann (Belden) HiLCOS OpenBAT 8.80-REL to 10.12-RU1
  • Hirschmann (Belden) HiLCOS BAT450 8.80-REL to 10.12-RU1

Timeline

  • 2026-04-03: disclosed
  • 2026-04-03: advisory

References