The September 2019 table reports 7,788,320 IPv4 addresses responding on TCP port 23 and 4,648,376 on port 1883. These are port observations, not confirmed Telnet devices or unauthenticated MQTT brokers.
Method and evidence limits
The original analysis used four months of Project Sonar TCP SYN observations. Source manifests, scan exclusions and extraction outputs have not been reproduced for this update. The original numerical tables are retained as historical reported results.
A SYN response establishes an open TCP port in the test. Application identification requires additional protocol probes. This dataset does not establish MQTT authentication, accepted topics, TLS negotiation, Telnet login access, device type or compromise.
CoAP is not measured here. A TCP-only dataset cannot substitute for a study of typical UDP CoAP deployments. IPv6 and devices unreachable from the scanner are also outside the scope.
MQTT- and Telnet-associated port counts
The table's historical service and encryption labels denote conventional port use. They do not verify that protocol or encryption was actually negotiated. Each cell counts responding addresses on that port; addresses may occur in several columns.
| Month | MQTT 1883 (Unencrypted) | MQTT/TLS 8883 (Encrypted) |
|---|---|---|
| Jun 2019 | 5,697,253 | 4,966,067 |
| Jul 2019 | 4,868,528 | 3,888,479 |
| Aug 2019 | 5,724,310 | 4,647,523 |
| Sep 2019 | 4,648,376 | 3,887,681 |
| Month | Port 23 (Standard) | Port 2323 (Alternate) | Port 9527 (Cameras) |
|---|---|---|---|
| Jun 2019 | 7,512,097 | 3,674,547 | 4,516,795 |
| Jul 2019 | 7,632,009 | 3,481,424 | 3,486,753 |
| Aug 2019 | 7,790,619 | 3,483,178 | 3,567,684 |
| Sep 2019 | 7,788,320 | 3,469,284 | 3,478,730 |
From June to September, reported port-1883 responses fell 18.4% and port-8883 responses fell 21.7%. Port 23 grew 3.7%, while port 2323 fell 5.6% and port 9527 fell 23.0%. The roughly 14.7 million responses across the three September Telnet-associated rows are not 14.7 million distinct devices.
What the observations do not establish
The port-1883 count does not measure unauthenticated subscriptions or plaintext application traffic. The port-8883 count does not establish valid TLS, client authentication or topic authorization. Comparing these rows therefore does not measure an encryption-adoption rate.
The declines cannot be attributed to security remediation, cloud migration or device retirement from these observations alone. A cloud-managed service can still have a publicly reachable endpoint; being hosted in a cloud does not make it invisible to scanning. Later legislation is not evidence of what caused a 2019 change.
Open Telnet and weak credentials can be dangerous in an actual device deployment, but this table contains no login attempts or malware observations. It cannot establish how many devices were vulnerable to a particular botnet or already compromised.
Verify an owned IoT deployment
- Inventory devices, firmware versions and their expected network paths.
- Check approved external addresses for unexpected listeners using the port scanner, then identify the actual service from trusted host or device configuration.
- For MQTT, verify transport encryption, authentication and topic-level authorization independently. Test only with owned accounts and harmless test topics.
- Disable unnecessary management services and restrict intended ones to trusted networks. Segment devices from unrelated systems and review router port-forwarding rules.
- Apply supported firmware updates and replace devices whose security support has ended.
For the wider historical port table, see IPv4 service exposure. For any trend claim, retain snapshot dates, IP-set deduplication and protocol-confirmation evidence so another analyst can reproduce it.

