Skip to main content
DNS Checker(beta)
IoT Port Exposure: Historical MQTT and Telnet Scan Observations
Updated 3 min read

IoT Port Exposure: Historical MQTT and Telnet Scan Observations

Ishan Karunaratne

Ishan Karunaratne

Software Architect & Infrastructure Engineer

The September 2019 table reports 7,788,320 IPv4 addresses responding on TCP port 23 and 4,648,376 on port 1883. These are port observations, not confirmed Telnet devices or unauthenticated MQTT brokers.

Method and evidence limits

The original analysis used four months of Project Sonar TCP SYN observations. Source manifests, scan exclusions and extraction outputs have not been reproduced for this update. The original numerical tables are retained as historical reported results.

A SYN response establishes an open TCP port in the test. Application identification requires additional protocol probes. This dataset does not establish MQTT authentication, accepted topics, TLS negotiation, Telnet login access, device type or compromise.

CoAP is not measured here. A TCP-only dataset cannot substitute for a study of typical UDP CoAP deployments. IPv6 and devices unreachable from the scanner are also outside the scope.

MQTT- and Telnet-associated port counts

The table's historical service and encryption labels denote conventional port use. They do not verify that protocol or encryption was actually negotiated. Each cell counts responding addresses on that port; addresses may occur in several columns.

MonthMQTT 1883 (Unencrypted)MQTT/TLS 8883 (Encrypted)
Jun 20195,697,2534,966,067
Jul 20194,868,5283,888,479
Aug 20195,724,3104,647,523
Sep 20194,648,3763,887,681
MonthPort 23 (Standard)Port 2323 (Alternate)Port 9527 (Cameras)
Jun 20197,512,0973,674,5474,516,795
Jul 20197,632,0093,481,4243,486,753
Aug 20197,790,6193,483,1783,567,684
Sep 20197,788,3203,469,2843,478,730

From June to September, reported port-1883 responses fell 18.4% and port-8883 responses fell 21.7%. Port 23 grew 3.7%, while port 2323 fell 5.6% and port 9527 fell 23.0%. The roughly 14.7 million responses across the three September Telnet-associated rows are not 14.7 million distinct devices.

What the observations do not establish

The port-1883 count does not measure unauthenticated subscriptions or plaintext application traffic. The port-8883 count does not establish valid TLS, client authentication or topic authorization. Comparing these rows therefore does not measure an encryption-adoption rate.

The declines cannot be attributed to security remediation, cloud migration or device retirement from these observations alone. A cloud-managed service can still have a publicly reachable endpoint; being hosted in a cloud does not make it invisible to scanning. Later legislation is not evidence of what caused a 2019 change.

Open Telnet and weak credentials can be dangerous in an actual device deployment, but this table contains no login attempts or malware observations. It cannot establish how many devices were vulnerable to a particular botnet or already compromised.

Verify an owned IoT deployment

  1. Inventory devices, firmware versions and their expected network paths.
  2. Check approved external addresses for unexpected listeners using the port scanner, then identify the actual service from trusted host or device configuration.
  3. For MQTT, verify transport encryption, authentication and topic-level authorization independently. Test only with owned accounts and harmless test topics.
  4. Disable unnecessary management services and restrict intended ones to trusted networks. Segment devices from unrelated systems and review router port-forwarding rules.
  5. Apply supported firmware updates and replace devices whose security support has ended.

For the wider historical port table, see IPv4 service exposure. For any trend claim, retain snapshot dates, IP-set deduplication and protocol-confirmation evidence so another analyst can reproduce it.

Frequently Asked Questions

Sources

This article was researched and structured by the author with AI assistance for drafting and technical verification.

About the Author

Ishan Karunaratne
Ishan Karunaratne

Software Architect & Infrastructure Engineer

US Army veteran with a B.S. in Information Technology, CompTIA A+, Network+, and Security+ certified. 20+ years building and securing web infrastructure.

B.S. Information Technology, Online SystemsCompTIA A+ (2009)CompTIA Network+ (2009)CompTIA Security+ (2009)US Army Veteran, Operation Iraqi Freedom

Share this article

DNS terms in this guide

Plain-English definitions for the key terms referenced above.

Related Articles

Typo-Like Nameservers: Investigating 145,061 Historical Delegations

A historical pipeline flagged 145,061 delegations to a typo-like nameserver domain. Similar spelling alone does not establish malicious control or takeover.

What Happens When One DNS Provider Goes Down: The Hidden Fragility of TLD Ecosystems

Historical DNS provider concentration figures illustrate shared failure risk. Read the reported counts alongside unresolved denominator and corpus limits before using them as current market shares.

How Expired Name Servers Become Domain Hijacking Vectors

Historical nameserver-delegation candidates illustrate why owners should verify authority, provider status and domain control. An expiry-looking hostname does not prove takeover risk.

Why DNSSEC Is Still Failing: Lessons from 240 Million Domains

Historical zone snapshots reported low parent-DS presence. Examine the measurement limits, provider incentives, and operational reasons DNSSEC deployment can remain incomplete.