Mosquitto is the reference open source MQTT broker, and it is small enough to run almost anywhere. A ZoomEye query for the application fingerprint records 1,160,264 matches.
How the number was obtained
The query was app="Mosquitto", run against the ZoomEye index on 29 September 2026 at 02:47 UTC. The unit is a fingerprint match on an internet reachable service. The number counts hosts that ZoomEye can identify as Mosquitto, and it does not indicate whether any of them are misconfigured, unpatched, or exposed without authentication. Those are separate questions that require inspection of an individual deployment.
Why the population is large
The broker sits inside a long list of products. Home automation platforms, sensor gateways, vehicle telemetry, building systems, and industrial gateways commonly embed an MQTT broker to move small messages between devices. Deployment instructions for these projects frequently leave the listener on port 1883 with a default configuration, because the intended consumer is a local network.
Publishing the broker to the internet is what turns a local convenience into a shared surface. Several of the documented methods, such as a cloud bridge or a port forward, are one line of configuration away from a device that someone set up in an afternoon.
What the exposure does and does not mean
An open MQTT listener that allows anonymous connections lets any client subscribe to every topic the broker handles, and publish to them as well. Where the broker controls physical equipment, the consequence is operational rather than informational.
A fingerprint match is not proof of that condition. Many of these hosts will require credentials, and some will sit behind a filter that the index reached from a different vantage point.
What to check
Confirm whether the broker needs to be reachable from the internet at all. Where it does, require authentication and TLS on the listener, disable anonymous access explicitly, and restrict the topic tree so that a client issued for one device cannot subscribe to everything. Log connection attempts and alert on new client identifiers.
For the wider estate, the count is a reminder that infrastructure built for a local network keeps appearing on the global one.
References
- ZoomEye search result for app="Mosquitto", retrieved 29 September 2026.
- Eclipse Mosquitto project documentation: https://mosquitto.org/man/mosquitto-conf-5.html
- OASIS MQTT Version 5.0 specification: https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html
Top comments (0)