DASAN Newtork Solutions — 2 prefixes (MA-L)
Summary
- // what this is
- DASAN Newtork Solutions is registered to MAC prefix
DC:49:65and 1 more in the IEEE OUI database. When a device's MAC address begins withDC:49:65, that block was registered by DASAN Newtork Solutions — the OUI identifies the maker of the network hardware, which is not always the brand on the device. - // analyst note
- A DASAN OUI on a globally-administered address = genuine DASAN access hardware; useful for ISP/SMB classification. Given the deployed-CPE CVE history, prioritize patch/hardening checks where these devices appear.
About this vendor.
Two MA-L OUI blocks — DC:49:65 and F4:27:56 — are registered to "DASAN Newtork Solutions," with the misspelling ("Newtork," missing the second "w") present in the IEEE registry itself; the same vendor's correctly-spelled blocks (24:43:E2, 64:68:1A under "DASAN Network Solutions") and the parent's "DASAN Networks, Inc." blocks (54:AE:D0, 18:2C:A9) are distinct registry entries for related entities under the DASAN group. DASAN Network Solutions is a South Korean telecom access-equipment maker, a wholly-owned subsidiary spun off in April 2015 from the KOSDAQ-listed parent DASAN Networks Inc. (established 1993 as DASAN Engineering, renamed 2002). Its hardware is carrier/ISP gear, not retail: GPON/XGS-PON ONTs and OLTs, EPON/10G-EPON ONUs, Ethernet L2/L3 switches, xDSL/G.fast CPE, and Wi-Fi residential gateways deployed by operators such as SoftBank, Chunghwa Telecom, KT, SK Broadband, and Viettel. The device class carries a notable security history: the 2018 GPON home-router chain CVE-2018-10561 (auth bypass) + CVE-2018-10562 (unauthenticated command injection) gave full unauthenticated RCE and was actively exploited by the Satori botnet across an estimated ~240,000 near-end-of-life devices. More recent H660WM ONU advisories — CVE-2025-29525 (insecure default credentials, CVSS 5.3) and CVE-2025-44178 (WAN-side UPnP improper access control), both published 2025-08-25 — show the recurring pattern of network-accessible, no-auth-required weaknesses in this deployed CPE class. IEEE publishes no OUI assignment dates, so no registration date is recorded here.
- IEEE assignment
- 2 prefixes → DASAN Newtork Solutions (typo as in registry), registered DASAN Tower, Bundang-gu, Seongnam-si, Gyeonggi-do, KR 13493 [Confirmed] — IEEE MA-L (rows for DC4965, F42756)
- Registry / block size
- MA-L (24-bit OUI); 2 IEEE prefixes [Confirmed] — IEEE MA-L. NOTE: IEEE's public OUI data publishes NO assignment/registration date; any "date registered" on third-party tools is a database artifact, not an IEEE fact.
- Registry org-name typo
- registry value is "DASAN Newtork Solutions" (missing "w"); correctly-spelled "DASAN Network Solutions" exists for prefixes 64:68:1A and 24:43:E2, and "DASAN Networks, Inc." for 54:AE:D0 / 18:2C:A9 — related entities under the DASAN group [Confirmed] — IEEE MA-L
- HQ / country
- registry address DASAN Tower, 49 Daewangpangyo-ro 644beon-gil, Bundang-gu, Seongnam-si, Gyeonggi-do 13493, KR; corporate HQ of DASAN Network Solutions in Gwacheon-si, Gyeonggi-do, South Korea [Confirmed] — IEEE MA-L; https://dasanns.com/en/company/outline.php
- Company status
- active; wholly-owned subsidiary spun off April 2015 from KOSDAQ-listed parent DASAN Networks Inc. (est. 1993 as DASAN Engineering Co., Ltd; renamed DASAN Networks Inc. 2002; DNS subsidiary originally incorporated 2010 in the USA)[Confirmed] — https://en.wikipedia.org/wiki/DASAN_Networks ; https://dasanns.com/en/company/outline.php
- Device types
- GPON/XGS-PON ONTs (H640/H660/H665/H670 series), EPON/10G-EPON ONUs, GPON OLT systems (M8106, V5812G), Ethernet L2/L3 switches, xDSL/G.fast CPE, Wi-Fi residential gateways, mobile backhaul, private-5G — carrier/ISP equipment, not retail[Confirmed] — https://dasanns.com/en/solution/list.php ; https://dasanns.com/en/company/business.php
- Notable products
- GPON ONT/OLT access line
- Verified sample prefixes (this entry, both MA-L, "DASAN Newtork Solutions")
- DC:49:65, F4:27:56 [Confirmed] — IEEE MA-L
- Notable customers
- SoftBank (JP), Chunghwa Telecom (TW), Viettel (VN), KT, SK Broadband, LG U+ (KR); deployed across 60+ operators in 25+ countries [Likely] — https://www.netmanias.com/en/dasan-networks/about/10/ ; https://dasanns.com/en/company/outline.php
- Security note
- GPON CPE class has a documented unauthenticated-access history — 2018 chain CVE-2018-10561 (auth bypass) + CVE-2018-10562 (command injection) → full RCE, exploited by Satori botnet, ~240K devices (vendor figure; early press overstated at 1M+); 2025 H660WM ONU CVE-2025-29525 (default creds, CVSS 5.3 Medium) and CVE-2025-44178 (WAN UPnP improper access control), both published 2025-08-25 [Confirmed] — https://nvd.nist.gov/vuln/detail/CVE-2025-29525 ; https://nvd.nist.gov/vuln/detail/CVE-2025-44178 ; https://www.bitdefender.com/en-us/blog/hotforsecurity/rce-vulnerability-affects-1-million-dasan-routers
- Analyst note
- A DASAN OUI on a globally-administered address identifies genuine DASAN access hardware (carrier-deployed ONT/OLT/switch), useful for ISP/SMB asset classification; given the deployed-CPE CVE history, treat such devices as a hardening/patch-status priority on networks where they appear.