Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Freeswitch

First CVE: Sep 30, 2013Active for: 13 yearsTotal CVEs: 21
50.8
VTI Score
TOP TARGET

Freeswitch is an open-source telecommunications platform and soft-switch engine widely deployed in VoIP infrastructure, carrier networks, and unified communications systems, presenting a strategically important but narrowly scoped attack surface. Vulnerabilities affecting the platform skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through memory-safety and authentication-handling weakness classes including improper authentication, input-validation failures, out-of-bounds writes, heap-based buffer overflows, and buffer-boundary violations that are characteristic of a large native codebase handling untrusted protocol data. The exposure concentrates entirely within the core Freeswitch product itself, making patch adoption and deployment segmentation critical for operators relying on this platform. Defenders should monitor this vendor's releases closely and treat critical advisories as high-priority in call-processing tiers; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Freeswitch over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2013
12 years ago
Most Recent CVE
Jun 9, 2026
45 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-19492CRITICAL
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
Dec 2, 20199.858NOYES
CVE-2026-49841CRITICAL
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar
Jun 9, 20269.837NONO
CVE-2026-49840CRITICAL
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar
Jun 9, 20269.135NONO
CVE-2026-49847HIGH
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar
Jun 9, 20267.530NONO
CVE-2026-49842HIGH
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar
Jun 9, 20267.528NONO
CVE-2026-49475HIGH
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar
Jun 9, 20267.528NONO
CVE-2026-45771HIGH
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar
Jun 9, 20267.528NONO
CVE-2026-49843MEDIUM
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar
Jun 9, 20265.326NONO
CVE-2021-37624HIGH
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar
Oct 25, 20217.526NONO
CVE-2021-41145HIGH
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwar
Oct 25, 20217.525NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
33%
52%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (90.5%)
Unknown2 (9.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (76.2%)
High3 (14.3%)
Unknown2 (9.5%)
User Interaction
None18 (85.7%)
Unknown2 (9.5%)
Required1 (4.8%)
Privileges Required
Low3 (14.3%)
High0 (0.0%)
None16 (76.2%)
Unknown2 (9.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.8% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Freeswitch.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Freeswitch — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Freeswitch's Products

View all 3 CNAs →

Top CWEs