deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

ZoomEye fingerprint search counts 12,055 Tenda devices exposed, versus 426,677 title matches

A dev.to analysis measuring exposure for CVE-2026-104610 shows why fingerprint-based ZoomEye queries give a more accurate count of internet-reachable Tenda gateways, while title searches inflate the figure roughly 35-fold.

ZoomEye fingerprint search counts 12,055 Tenda devices exposed, versus 426,677 title matches

A measurement exercise published on dev.to highlights how easily exposure numbers for consumer networking equipment can be misread. The subject was CVE-2026-104610, a vulnerability affecting Tenda's HG7, HG9 and HG10 fibre gateways, and the question was how many such devices can be found from the public internet.

Two queries, two very different answers

The author ran two searches against ZoomEye, an internet-wide device search engine, on 4 October 2026. A query for pages with "Tenda" in the HTML title returned 426,677 matching services. A query using ZoomEye's Tenda application fingerprint returned 12,055.

The gap matters. According to the write-up, the title query catches anything carrying the vendor's name in its title, including product pages, reseller listings and documentation mirrors, alongside actual router interfaces. Real devices often present a generic login string or a model number rather than the brand name, so the title query over-counts non-devices and under-counts gateways within the same result set. The application fingerprint, built from how a device responds rather than what it calls itself, is the sounder basis for counting, which makes 12,055 the figure worth citing.

Neither number identifies the vulnerable models

The candid limitation in the piece is that neither query can tell you which devices are the affected HG7, HG9 or HG10 units. These are carrier-supplied fibre terminals, and carrier-grade deployments rarely advertise a marketing title. A device may answer HTTP with a minimal page and a firmware string, which is what the fingerprint is derived from, but a fingerprint still cannot confirm the specific model.

The broader lesson drawn is about exposure measurement in general: for consumer and carrier equipment, the link between searchable metadata and the genuinely affected population is weak. What a search engine measures is how findable devices are, not how many vulnerable units are actually deployed.

What the 12,055 figure is good for

The fingerprint count still serves a purpose. It establishes that a meaningful population of Tenda-fingerprinted assets is reachable from the internet, which is what would make remote exploitation of the CVE possible in the first place. It also sets the scale of any coordinated response somewhere in the thousands rather than being a trivial handful of boxes.

For operators, the suggested workflow is to pair the fingerprint with a scope filter. Adding a country, organisation or CIDR term to the same query converts an internet-wide count into an exposure number for infrastructure you actually own or manage, which is the form of the measurement that can support a decision.

Remediation and detection

The write-up notes that the remediation path does not depend on the count. According to the author, the exploit for CVE-2026-104610 is public and requires no authentication, so wherever a vulnerable gateway exposes its management interface on the WAN side, that exposure should be closed first. Restricting management access to an administrative VLAN and removing the WAN-side listener are controls that work whether or not a vendor fix has shipped.

For interim detection, the piece points to a specific signature: requests to /boaform/formLoopBack carrying an unusually long Ethtype value stand out, and an alert on that pattern is inexpensive to deploy.

Why it matters

Exposure numbers drive priorities, and this exercise shows how the wrong query can inflate a figure by a factor of roughly 35. Anyone quoting 426,677 as a count of Tenda devices would be counting shop pages alongside routers while missing units that never put the brand in their title. The disciplined alternative, fingerprints combined with scope filters, gives defenders a number they can act on within their own ranges.

At the same time, the piece is honest about the ceiling of external measurement. An internet-wide index can show that Tenda gear is reachable, but it cannot confirm which units are the affected models. That answer has to come from the carrier or from the device itself, and no external search engine can substitute for that step.

  • #security
  • #vulnerability
  • #tenda
  • #zoomeye
  • #networking

Related posts