“To recap: An employee of SignalWire (which develops FreeSWITCH) came right out and said they would let people who aren’t paying for FreeSWITCH Advantage stay vulnerable until their regularly scheduled release (sometime in the Summer).”

Soatok opened FreeSWITCH’s source after Salt Typhoon and found a buffer overflow almost immediately. The vendor patched it on GitHub but will not ship a community release until summer. Paying customers get the fix first. About 8,300 exposed instances wait.