· via dev.to (home feed)
ZoomEye scan sizes internet exposure of SonicWall SMA1000 gateways after zero-day chain
A ZoomEye fingerprint query found only seven positively identified internet-facing SonicWall SMA appliances, while Shadowserver counted several hundred exposed SMA1000 units during the September 2026 disclosure window.

Advisory met a measurement
SonicWall published advisory SNWLID-2026-0016 on September 1, 2026, disclosing a zero-day chain affecting its SMA1000 Secure Mobile Access appliances, and CISA added the vulnerabilities to its Known Exploited Vulnerabilities Catalog a day later. A dev.to analysis published on September 19 asked the question such advisories rarely answer: how many of these gateways can actually be reached from the open internet?
To size the exposure, the author turned to ZoomEye, a search engine for internet-connected devices. A fingerprint query for the product, app="SonicWall-SMA", run against ZoomEye's IPv4 device dataset, returned 7 matching records at the time of collection. A free-text search for "SonicWall SMA" across all of ZoomEye's data types returned 416 records.
Two counts, two methods
According to the analysis, the distance between those figures is methodological rather than contradictory. A fingerprint query only matches services the scanner can identify with confidence from their banners, while a free-text search also picks up pages and services that merely reference the product without exposing an appliance interface. For judging real exposure, the author treats the fingerprint count as the stricter, more defensible number.
Seven devices might look like good news, but the analysis warns against reading it that way. Shadowserver Foundation tracking during the September 2026 disclosure window counted several hundred SMA1000 instances exposed to the public internet. The gap, the author explains, comes down to observation: Shadowserver watches traffic and scanning behavior, whereas a fingerprint match requires the appliance to present a recognizable banner on whatever port gets scanned. Both figures describe the same underlying reality — a meaningful population of authentication gateways sits directly on the internet, and its apparent size depends on how you count.
What a measurement like this is for
ZoomEye's value is not a precise census, the analysis argues, but the ability to answer three practical questions quickly:
- Is this product class exposed at all? Any non-zero fingerprint result proves live internet-facing instances exist, so the exposure is not merely theoretical.
- Where does the exposure concentrate? A country facet shows distribution. As an illustration of how facets turn a raw number into a prioritization input, a query for Modbus returned 9,820 records, with the largest concentrations in Cyprus (3,986), the United States (916) and Sweden (898).
- Did exposure change after disclosure? Running the same query over time shows whether organizations are shrinking their footprint; a count that holds steady after a heavily publicized zero-day says something about how patching is going.
Making the number reproducible
A measurement only counts as evidence if someone else can repeat it. The analysis lists four details that belong with any ZoomEye figure: the exact query string, including operators and quoting; the dataset, because IPv4 device data, IPv6 data and web data return different populations; the collection time, since exposure shifts; and the unit — a single record represents one service observed on one address, which is not the same as one distinct organization. Leave any of those out, the author writes, and the figure becomes anecdote rather than evidence. The article's references state that its figures come from ZoomEye's combined dataset, collected on 2026-09-20.
The workflow the author proposes
The recommended sequence is simple. Search for the product fingerprint to establish whether exposure exists. Add geographic and organizational facets to see where it clusters. Compare the results against internal inventory to surface instances nobody knew about. Then re-run the query after remediation to confirm the exposure actually shrank. According to the analysis, this final verification step is the one organizations most often skip, yet it is the only one that proves the work.
The broader point is that exposure data answers a question vulnerability scanners cannot: whether an attacker with no authorized route into the network can reach a vulnerable system. For an edge appliance, the author writes, that distinction effectively defines the risk.
Why it matters
The SMA1000 is an authentication gateway, the sort of device placed at the network edge to broker remote access to internal resources. When a zero-day chain in hardware like that lands in CISA's Known Exploited Vulnerabilities Catalog, defenders need to know their own exposure, not just a severity rating. The dev.to piece demonstrates two things at once: that the exposure is real and non-trivial, given Shadowserver's count of several hundred internet-facing units, and that scanner counts can differ by orders of magnitude depending on method. Anyone triaging the advisory should therefore treat published numbers as method-dependent, run a reproducible query against their own environment, and re-run it after patching to confirm the edge actually got smaller.
- #sonicwall
- #zero-day
- #network-security
- #zoomeye
- #attack-surface