Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
ZoomEye can show which internet-facing hosts its index associates with a specific gateway product, such as a Cisco ASA SSL VPN. What a hit means is narrower than many readers assume. It is an indexed observation: evidence that the search engine recorded matching data at some point. It is not proof that the gateway is reachable today, exploitable, or compromised. This guide explains how to build a responsible search, what the results can and cannot establish, and what an asset owner should do once a result is confirmed as theirs. Keep every search within address space and assets you are authorized to assess.
What ZoomEye indexes and what you can ask it
ZoomEye’s official API documentation describes four kinds of access: asset search, vulnerability lookup and search, account quota information, and queries for bug-bounty assets. For gateway discovery, asset search is the relevant one. The ZoomEye Team’s published search guide lists the fields you can filter on:
- Application and product fingerprints
- Services and device type
- Operating system
- Ports
- HTML title and body
- HTTP headers
- SSL information, along with other filters
The guide documents conjunction, disjunction, negation, and grouping, as well as fuzzy and exact matching. Every search is scoped to one data subtype: IPv4 devices, IPv6 devices, web properties, or all data. The subtype determines which kind of record you are searching, so choose it before you write the query.
Recommended Free Tools
How do I find an exposed VPN gateway in ZoomEye?
Start with a product fingerprint, not the word “VPN.” A generic term matches any indexed page that contains it in a title, body, or header, including login pages, documentation, and marketing copy. A fingerprint for a specific application is far narrower. The guide’s published example is app="Cisco ASA SSL VPN". That example demonstrates syntax; it does not indicate how common the product is or how completely ZoomEye fingerprints it. Other gateways may need different fingerprints, and the guide does not promise a complete list. Build yours from the guide’s field vocabulary and from how your own deployment presents itself on its login page and in its headers.
#1 Best Overall
- Ubiquiti Networks networks networks Unifi security Gateway Pro 4-Port (USG-PRO-4)
- 4 Gigabit RJ45 ports plus 2 Gigabit SFP ports for fiber connectivity If needed
- Standard rack mount 1U size
- Provide cost-effective, reliable routing and advanced security for your network
- Max. Power Consumption:7W
Then work through the search in this order:
- Define the authorized scope. Write down the IP ranges, domains, and subsidiaries you are permitted to assess. Anything outside that list stays out of scope, however it appears in results.
- Start narrow. Use a specific application or product fingerprint, then add service, device, port, organization, or geography conditions that match what your inventory says should exist. Confirm field names and operator syntax in the current search guide before you run a combined query.
- Choose the correct subtype. Use IPv4 devices or IPv6 devices for network-level gateways, and web properties for portals served over HTTP(S). Use all data only when you cannot tell in advance which record type you need.
- Check your quota. Read the account quota information through the API before running large queries. Quota and plan limits determine how much you can query.
- Log the query and the observation time. Record the exact query string, the subtype, the date you ran it, and the timestamp on each result. Search-engine observations age, and a log is the only way to show later what you saw and when.
- Treat every hit as a lead. Match each address or domain against your CMDB, cloud accounts, and network records. Then confirm the owner, service, software version, and current exposure through approved internal channels. A hit on its own never justifies testing a system you do not own.
Does a ZoomEye result mean the gateway is vulnerable?
No. A match supports one modest claim: the search engine indexed data that matched your query. It does not, by itself, show that the gateway is reachable right now, that it belongs to the organization you suspect, that it can be exploited, that its credentials are weak, or that it has been compromised. Each of those points requires evidence from the asset owner’s own records and the system’s current state.
Vulnerability lookups are not host findings
ZoomEye’s API also offers vulnerability lookup and search. A vulnerability entry describes a flaw associated with a product. Whether your specific gateway is affected depends on its exact product, version, configuration, and patch level, which you confirm on the device itself or in your management records.
Rank #2
- Ubiquiti Networks networks networks Unifi security Gateway Pro 4-Port (USG-PRO-4)
- 4 Gigabit RJ45 ports plus 2 Gigabit SFP ports for fiber connectivity If needed
- Standard rack mount 1U size
- Provide cost-effective, reliable routing and advanced security for your network
- Max. Power Consumption:7W
Freshness
The 2025 SIGCOMM paper Censys: A Map of Internet Hosts and Services compared internet host and service search engines and found that data freshness varied substantially among them. In that study’s sample, some services reported in ZoomEye were more than three years old. Read this as a finding about one sample from a 2025 study, not a current freshness measurement. It is now October 2026, and ZoomEye’s documentation does not promise a universal freshness guarantee, so check the timestamp on every result before you describe it as current.
Coverage
The same paper found that no engine achieved complete coverage of the services reported by the others. An empty result on ZoomEye therefore says nothing definitive about your exposure; your own inventory and an authorized assessment remain the authority. The paper’s coverage figures are sampled for particular countries and protocol groups, plus a sampled all-port estimate for one engine. They are not ZoomEye-wide performance numbers, and ZoomEye’s documentation does not state a complete gateway-fingerprint coverage figure.
Rank #3
- 【Compatible with 30+ VPN service providers】Pre-installed with OpenVPN and WireGuard. OpenVPN speeds up to 150 Mbps; WireGuard speeds up to 355 Mbps. ***NO Wi-Fi function***
- 【Full Protection for Your Network】 Cloudflare encryption supported to protect the privacy. IPv6 security protocol supported. (To enable IPv6 function, please access to Admin Panel -> NETWORK -> IPv6.)
- 【Support VPN Cascading】Allow VPN server and VPN client operate simultaneously within the same device, enabling user to access local network servers with accessing public internet as a VPN client in the meantime.
- 【Ideal Gateway for Hosting a VPN Server at Home or Office】Access sensitive information stored under a corporate private network or access local files and bypass geo-blocking securely while working remotely.
- 【Advanced Hardware Specification】Equipped with 2.5 gigabit WAN port, 1 gigabit LAN port with USB 3.0 port, as well as 8 GByte EMMC (embedded multimedia card) storage for offline data storage.
One engine’s collection method does not describe another’s
Censys’s public scanning methodology states that its scans gather information without trying to log in, access databases, or gain authenticated access. That statement describes Censys only. Do not carry it over to ZoomEye. Verify how any platform collects its data from that platform’s own documentation before you rely on its observations.
Comparing internet-exposure search platforms
If you compare ZoomEye with other exposure-search platforms, apply the same axes to each and record the date you ran each query:
Rank #4
- Designed for UniFi Controller-based networks, the USG is a reliable firewall/router solution for small business and home networking within the UniFi ecosystem.
- No Built-in WiFi – Requires Separate Access Points This is a wired security gateway only. WiFi is not included and must be provided by UniFi Access Points or other wireless solutions.
- UniFi Controller Integration Required Full setup, configuration, and monitoring are managed through UniFi Controller software, enabling centralized network management and advanced routing control.UniFi Controller Integration Required Full setup, configuration, and monitoring are managed through UniFi Controller software, enabling centralized network management and advanced routing control.
- High-Performance Routing Capabilities Supports up to 3 Gbps total line rate (packet size dependent) and up to 1M packets per second under ideal conditions, suitable for high-speed wired networks.
- Includes NAT, VPN support, VLAN segmentation, and UniFi security features for managing secure and segmented networks
- Freshness and age of observations, including the timestamp each record carries
- Port and protocol coverage, especially non-standard ports you would not check by default
- Product and gateway fingerprint coverage for the specific devices in your environment
- Geographic and network vantage points, which determine what each engine can see
- Search fields, query flexibility, API access, quota, and plan limits
- Whether a displayed observation has been independently validated, and when it was collected
Apply two cautions to any published comparison, including the 2025 study. Its results depend on its own scan, sample, dates, and data access, and parts of its methodology were constrained by API and pricing limits. A comparison built on one sample will not settle which platform suits your inventory. Test the platforms against assets you own.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What asset owners should do after validating a result
Once you have confirmed that an address or domain is yours and exposes the service in question, follow the sequence in CISA’s Internet Exposure Reduction Guidance, published June 4, 2025:
Best Value
- UBIQUITI UNIFI GATEWAY LITE
- Confirm the current state of the asset: owner, service, software version, and exposure.
- Determine whether the business genuinely needs the exposure.
- Remove or restrict any exposure that is not needed.
- Patch and harden any service that must remain public.
- Reassess routinely, because exposure changes as systems are added and retired.
CISA lists specialized asset-search platforms among possible visibility tools and states that naming them is not an endorsement.
Quick Recap
If the service is not needed
- Remove the public listener, or restrict access to the source addresses that genuinely need it.
- Record the decision and the date in your inventory, so the next search result can be matched against a known outcome.
If the service must stay public
- Apply current vendor patches and confirm the firmware or software version on the device.
- Replace devices or software that are no longer supported.
- Change default passwords.
- Enable multi-factor authentication wherever the product supports it.
- Route administrative access through a monitored jump host.
- Monitor traffic to and from the gateway.
- Reassess the exposure on a routine schedule.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

