deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

ZoomEye counts 2.16M OpenVPN, 1.2M Ivanti Connect Secure and 445,720 pfSense endpoints

A ZoomEye fingerprinting snapshot counted 2.16 million reachable OpenVPN endpoints, 1.2 million Ivanti Connect Secure gateways and 445,720 pfSense appliances, arguing the real risk lies beside the VPN entry point.

ZoomEye counts 2.16M OpenVPN, 1.2M Ivanti Connect Secure and 445,720 pfSense endpoints

The measurement

A fingerprinting exercise published on dev.to in October 2026 set out to count internet-reachable remote access appliances using the ZoomEye AI cyberspace search service. Queries executed on 20 September 2026 returned 2,163,654 OpenVPN endpoints, 2,508,736 SonicWall appliances, 1,225,643 Ivanti Connect Secure gateways and 445,720 pfSense installations. WatchGuard returned 31,255 matches and Sophos XG Firewall 1,604.

The author is careful about what these figures mean: each count describes assets matching a product fingerprint on a reachable address. The numbers do not confirm vulnerability, misconfiguration or exploitation.

Reachable by design

The post's framing inverts the usual exposure story. Remote access infrastructure exists to accept connections from untrusted networks, so reachability is not a misconfiguration but the design. An OpenVPN count in the millions is expected rather than alarming, and pfSense and SonicWall deployments typically present a reachable WAN interface in front of the network by definition.

The small numbers are read the same way. According to the post, the WatchGuard and Sophos XG figures most likely reflect fingerprints that resolve for only a subset of those vendors' deployments, not that the vendors have small installed bases.

Where the risk actually sits

The risk, the post argues, is not the reachable VPN endpoint but everything reachable alongside it. Four surfaces are called out:

  • Management interfaces that share an address with the VPN service, frequently with a weaker authentication story than the VPN itself.
  • Version banners that disclose which advisories apply to a device before any exploitation attempt, lowering the cost of targeting.
  • Pre-authentication parsing paths, including certificate handling, SAML assertion processing and session establishment, where a flaw is by definition reachable by an unauthenticated caller.
  • The trust the device holds: certificates, keys and often directory credentials, which means a compromise places an attacker inside the trust boundary rather than outside it.

What the counts do and do not support

A count of 2.16 million OpenVPN endpoints is not a count of vulnerable VPNs. What it supports is a scoping argument: because this class of device is reachable by design, the population that could be affected by a flaw in it is approximately the population deployed, with no segmentation to shrink the number. That distinguishes it from an exposed database, where the correct remediation is to remove the exposure. For a VPN endpoint, the exposure is the service.

What to check

The post lays out an inventory checklist for this estate. Record vendor, model and firmware version, and log the address the service answers on separately from the address the management interface answers on, since the two frequently differ. Confirm the management plane is not on the public path, described as the control that most often fails. Keep versions current, because for a device that must be reachable the patch is the primary control. Check the authentication configuration, since certificate-only, MFA-enforced and password-only deployments produce the same fingerprint while carrying different risk profiles. Finally, re-measure after changes: a management interface moved behind an authenticated path should disappear from a public query.

Why it matters

The measurement puts a size on the attack surface of perimeter infrastructure. The OpenVPN, Ivanti Connect Secure and pfSense figures alone add up to nearly 3.9 million instances, before the larger SonicWall number is counted. Per the post, this is why pre-authentication flaws in remote access appliances repeatedly attract the fastest remediation timelines in the industry: a flaw in a reachable-by-design device is exploitable by anyone who can route to it, which is effectively everyone, with no reconnaissance barrier, no internal foothold and no user interaction to engineer, and the device itself sits on trust material.

For defenders, the practical takeaway is not the global totals but the delta between what is publicly reachable and what an organisation has documented. An appliance answering on a public address that nobody has recorded is the finding worth acting on.

  • #vpn
  • #network-security
  • #openvpn
  • #ivanti
  • #pfsense
  • #zoomeye