5VT Technologies — D4:BD:1E (MA-L)
Summary
- // what this is
- 5VT Technologies, Taiwan is registered to MAC prefix
D4:BD:1Ein the IEEE OUI database. When a device's MAC address begins withD4:BD:1E, that block was registered by 5VT Technologies, Taiwan — the OUI identifies the maker of the network hardware, which is not always the brand on the device. - // analyst note
- 5VT Technologies is a real, identifiable Taipei-based fabless SoC/software vendor with a documented product history and two actively-exploited 2025 CVEs against its flagship embedded software — enough to move past a bare shell registration — but it holds only this single OUI, and the vendor site could not be fetched directly this session.
About this vendor.
A MAC address starting with D4:BD:1E belongs to 5VT Technologies, a Taipei, Taiwan-based fabless semiconductor and embedded-software vendor, typically seen on VoIP and broadband-gateway hardware rather than consumer laptops or phones.
The IEEE registry lists a single MA-L assignment for this registrant: D4:BD:1E, recorded as "5VT Technologies,Taiwan LTd." at 6F, No. 19-9, SanChong Rd., Nangang Dist, Taipei TW 11501. No second MA-L, MA-M, or MA-S block was found under this or a closely matching name in the local registries.
The company itself is substantive, not a bare registration. A 2006 press release describes a licensing deal with HelloSoft for VoIP software integrated into the 5VT1310, an ARM9-based single-chip SoC for IP phones, VoIP ATAs, and VoIP/VoWLAN gateways, naming CEO Jackson Chang. The company has since expanded into GPON/XGSPON and switch SoCs, joined the Broadband Forum in 2010, and per search-indexed site content now also ships the "Blue Angel Software Suite," embedded Linux management software for broadband/VoIP gateway devices.
Security researchers have since flagged that same software line. Two CVEs published 2025-06-23 target the Blue Angel Software Suite's web management interface: CVE-2025-34033, an OS command injection in webctrl.cgi (CVSS 7.7), and CVE-2025-34034, hardcoded/undocumented admin accounts (CVSS 9.3/8.8). Shadowserver recorded exploitation evidence as early as 2025-01-26, and a SANS ISC honeypot diary (2025-10-22) independently logged an in-the-wild exploit attempt against the same CGI endpoint.
Two caveats apply. The vendor's own site (5vtechnologies.com) could not be fetched directly this session — connections were refused — so company-history details are corroborated only through search-engine snippets, not a direct read. And the CVE linkage above rests on a vendor-name match, not a confirmed device-level MAC in the D4:BD:1E block, so treat it as likely rather than confirmed.
- Device class
- VoIP ATAs, VoIP/Wi-Fi phones, VoIP/VoWLAN and broadband/GPON/XGSPON gateways
- Vendor
- 5VT Technologies (also styled 5V Technologies), Taipei, Taiwan
- Registry
- IEEE MA-L, single assignment (D4:BD:1E); no MA-M/MA-S found
- Known vulnerabilities
- CVE-2025-34033 (command injection), CVE-2025-34034 (hardcoded credentials) in Blue Angel Software Suite
- IEEE assignment
- D4:BD:1E → 5VT Technologies, Taiwan Ltd., registered Taipei, TW [Confirmed] — the IEEE MA-L registry D4BD1E
- Registry / block size
- MA-L (24-bit OUI); single assignment found for this registrant (no MA-M/MA-S) [Confirmed] — the IEEE MA-L registry D4BD1E
- HQ / country
- 6F, No. 19-9, SanChong Rd., Nangang Dist, Taipei TW 11501 [Confirmed] — the IEEE MA-L registry D4BD1E
- Company history
- 2006 press release describes VoIP SoC licensing deal (5VT1310 chip, CEO Jackson Chang, HelloSoft partnership) [Likely] — https://www.design-reuse.com/news/13001/5v-licenses-hellosoft-voip-5vt-single-chip-solution.html
- Device types
- VoIP ATAs, VoIP/Wi-Fi phones, VoIP/VoWLAN gateways, broadband/GPON/XGSPON gateway hardware [Likely] — https://www.design-reuse.com/news/13001/5v-licenses-hellosoft-voip-5vt-single-chip-solution.html, http://www.5vtechnologies.com/products/voip/
- Notable products
- Blue Angel Software Suite (embedded Linux broadband/VoIP gateway management software); 5VT1310 ARM9 VoIP SoC [Likely] — https://www.vulncheck.com/advisories/5vtechnologies-blue-angel-command-injection
- Security history
- CVE-2025-34033 (OS command injection, webctrl.cgi, CVSS 7.7) and CVE-2025-34034 (hardcoded admin credentials, CVSS 9.3/8.8), published 2025-06-23; exploitation evidence from Shadowserver (2025-01-26 onward) and a SANS ISC honeypot diary (2025-10-22) [Likely — vendor-name match, not device-level MAC confirmation] — https://nvd.nist.gov/vuln/detail/CVE-2025-34034, https://www.vulncheck.com/advisories/5vtechnologies-blue-angel-hardcoded-credentials, https://isc.sans.edu/diary/32410
- Verified sample prefix
- D4:BD:1E [Confirmed] — the IEEE MA-L registry D4BD1E
- Analyst note
- single-OUI vendor with a documented product history and two actively-exploited 2025 CVEs against its flagship embedded software — enough to move past a bare registry entry — but the CVE-to-OUI link rests on a vendor-name match rather than a confirmed device MAC, and the vendor site itself was not directly reachable this session [Likely] — https://www.design-reuse.com/news/13001/5v-licenses-hellosoft-voip-5vt-single-chip-solution.html, https://www.vulncheck.com/advisories/5vtechnologies-blue-angel-command-injection