Finding the Exposed Controllers: Using ZoomEye to Locate Internet-Reachable EtherNet/IP Assets
Finding the Exposed Controllers: Using ZoomEye to Locate Internet-Reachable EtherNet/IP Assets On 30 July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published an alert stating that it was observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. The alert describes attackers…
On July 30, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning about a rise in cyber threats targeting programmable logic controllers (PLCs) within the Water and Wastewater Systems (WWS) sector. The threat actors were able to reach internet-exposed controllers, alter passwords, and change IP addresses.
This resulted in boil water notices and forced manual operations. While the alert does not specify a particular software flaw, it emphasizes the importance of locating internet-reachable EtherNet/IP assets, as these are the primary targets.
CISA advises critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet. They recommend utilizing VPNs or gateways for remote access instead of direct connections to the PLCs. The agency also suggests enabling password protection, changing default passwords, and implementing IP address allowlisting to restrict remote access to known engineering laptops or other critical OT assets.
However, there are two important limitations to note. Firstly, the alert does not provide a list of affected organizations, device counts, or a breakdown by vendor. Secondly, CISA mentions that cellular modems installed by operators, vendors, or system integrators, which may not be documented, can also be targeted. An inventory built solely from change-management records may be incomplete due to this limitation.
The alert specifically mentions Rockwell Automation MicroLogix 1400 PLCs and refers to Rockwell Automation's guidance on restoring access to such controllers when the password is unknown. Using ZoomEye to search for EtherNet/IP services on port 44818 returned 41,601 matching assets globally. This count is close to similar queries using only port or service filters, indicating a high number of EtherNet/IP exposed assets worldwide. However, these numbers do not indicate any attacks or specific ownership of WWS assets.
A more targeted query, such as querying for EtherNet/IP on port 44818 within the United States, returned 19,977 assets. While this figure represents EtherNet/IP exposure within one country, it does not specifically identify water-sector exposure. Vendor fingerprinting can be challenging due to the lean nature of the EtherNet/IP protocol, and relying solely on product-level fingerprints may not yield accurate results.
Instead, a protocol-level query is often more reliable, and operator records should be consulted to verify the presence of these devices.
To effectively turn the global count of EtherNet/IP exposed assets into a local inventory, organizations should use the protocol query as a filter over their actual address space, including public ranges and known remote-access endpoints such as cellular modems and vendor-managed links. By restricting the protocol query to these known ranges, any matches can be treated as devices that require ownership, purpose, and documented remote-access paths.
Comparing these matches against the organization's asset register will help identify any undocumented connections, which are particularly valuable as they represent the vulnerabilities highlighted in CISA's warning. Each confirmed match should be evaluated for direct access versus remote access through VPNs or gateways and whether password protection and IP allowlisting are properly implemented.
Ultimately, ZoomEye plays a crucial role in this workflow by identifying and scoping internet-reachable EtherNet/IP assets that would otherwise remain undocumented in change-management databases.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.