DASAN Networks, Inc. — 2 prefixes (MA-L)
Summary
- // what this is
- DASAN Networks is registered to MAC prefix
54:AE:D0and 1 more in the IEEE OUI database. When a device's MAC address begins with54:AE:D0, that block was registered by DASAN Networks — the OUI identifies the maker of the network hardware, which is not always the brand on the device. - // analyst note
- A MAC beginning 54:AE:D0 or 18:2C:A9 identifies genuine DASAN Networks, Inc.-registered hardware, most likely GPON/broadband CPE or switching gear; do not conflate with the similarly-named but registry-distinct DASAN Network Solutions / DASAN Newtork Solutions / DASAN CO., LTD. blocks, which are separate OUI assignments under different registrant-name rows.
About this vendor.
A MAC address starting with 54:AE:D0 or 18:2C:A9 belongs to DASAN Networks, Inc., a South Korean network-equipment maker, and typically identifies GPON/FTTH broadband CPE, Ethernet switches, xDSL gear, or wireless-access equipment rather than a general-purpose consumer device.
DASAN Networks traces to DASAN Engineering Co., Ltd., founded March 1993 in South Korea, which listed on KOSDAQ in 2000 and renamed itself DASAN Networks, Inc. in 2002. It is headquartered at DASAN Tower in Seongnam-si, Gyeonggi-do, and its product line spans FTTH/GPON, Ethernet switching, xDSL, wireless access, and security-switch equipment.
DASAN Networks is one of several similarly-named but registry-distinct DASAN entities: DASAN CO., LTD. (MA-L 18D071, 00D0CB), DASAN Network Solutions (MA-L 2443E2, 64681A), and DASAN Newtork Solutions [sic, a typo in the registrant name] (MA-L DC4965, F42756) each hold separate IEEE registrant-name rows and are not covered by this entry.
Security researchers disclosed CVE-2018-10561 (authentication bypass) and CVE-2018-10562 (command injection enabling remote code execution) in 2018, affecting DASAN-branded GPON home routers; over one million internet-exposed devices were found via Shodan, and the flaws were reported as actively exploited by the Hajime, Mettle, Mirai, Muhstik, and Satori botnets. No source located ties these CVEs specifically to OUI 54:AE:D0 or 18:2C:A9 as opposed to sibling DASAN/DZS product lines, so this is device-class corroboration only.
- IEEE assignment
- 2 prefixes → DASAN Networks, Inc., registered Bundang-gu, Seongnam-si, Gyeonggi-do, KR [Confirmed] — the IEEE MA-L registry 54AED0, the IEEE MA-L registry 182CA9
- Registry / block size
- MA-L (24-bit OUI); holds 2 confirmed IEEE prefixes under this exact registrant name [Confirmed] — the IEEE MA-L registry 54AED0, the IEEE MA-L registry 182CA9
- HQ / country
- DASAN Tower, 49, Daewangpangyo-ro, 644 Beon-gil, Bundang-gu Seongnam-si, Gyeonggi-do, KR 13493 [Confirmed] — the IEEE MA-L registry 54AED0
- Company status
- active; founded 1993 as DASAN Engineering Co., Ltd., KOSDAQ-listed 2000, renamed DASAN Networks, Inc. in 2002 [Confirmed] — https://en.wikipedia.org/wiki/DASAN_Networks
- Device types
- GPON/FTTH ONT home routers, carrier broadband CPE, Ethernet switches, xDSL equipment, wireless-access gear [Likely] — https://en.wikipedia.org/wiki/DASAN_Networks, https://device.report/dasan-networks
- Notable products
- GPON/FTTH optical network terminals, Ethernet switches, xDSL and wireless-access equipment [Likely] — https://en.wikipedia.org/wiki/DASAN_Networks
- Verified sample prefixes (both MA-L, DASAN Networks, Inc.)
- 54:AE:D0, 18:2C:A9 [Confirmed] — the IEEE MA-L registry 54AED0, the IEEE MA-L registry 182CA9
- Historic block
- none found for this registrant name [Unknown] — no source located
- Special note
- CVE-2018-10561 (authentication bypass) and CVE-2018-10562 (command injection / RCE) disclosed 2018 against DASAN-branded GPON routers; over one million internet-exposed devices found via Shodan; active exploitation reported by Hajime, Mettle, Mirai, Muhstik, and Satori botnets. Not confirmed as specific to OUI 54:AE:D0/18:2C:A9 versus sibling DASAN/DZS product lines. [Confirmed device-class; prefix-level tie Unknown] — https://nvd.nist.gov/vuln/detail/CVE-2018-10561, https://nvd.nist.gov/vuln/detail/CVE-2018-10562, https://www.securityweek.com/over-million-dasan-routers-vulnerable-remote-hacking/, https://www.bleepingcomputer.com/news/security/vulnerabilities-affecting-over-one-million-dasan-gpon-routers-are-now-under-attack/
- Related vendors
- DASAN CO., LTD. (MA-L 18D071, 00D0CB); DASAN Network Solutions (MA-L 2443E2, 64681A); DASAN Newtork Solutions [typo, separate existing entry] (MA-L DC4965, F42756) [Confirmed] — the IEEE MA-L registry 18D071, the IEEE MA-L registry 00D0CB, the IEEE MA-L registry 2443E2, the IEEE MA-L registry 64681A, the IEEE MA-L registry DC4965, the IEEE MA-L registry F42756
- Analyst note
- A MAC beginning 54:AE:D0 or 18:2C:A9 identifies genuine DASAN Networks, Inc.-registered hardware, most likely GPON/broadband CPE or switching gear; do not conflate with the similarly-named but registry-distinct DASAN Network Solutions, DASAN Newtork Solutions, or DASAN CO., LTD. blocks, which are separate OUI assignments under different registrant-name rows. [Confirmed]