HMS Industrial Networks — 6 prefixes (MA-L)
Summary
- // what this is
- HMS Industrial Networks is registered to MAC prefix
00:03:27and 5 more in the IEEE OUI database. When a device's MAC address begins with00:03:27, that block was registered by HMS Industrial Networks — the OUI identifies the maker of the network hardware, which is not always the brand on the device. - // analyst note
- Multiple confirmed OUI blocks plus identifiable product lines (Anybus, Ewon, Intesis, Ixxat, PEAK System, N-Tron, Red Lion) and an active ICS vulnerability-disclosure program establish company substance for this vendor entry.
About this vendor.
A MAC address beginning with a prefix like 00:30:56 or 00:05:94 belongs to HMS Industrial Networks (HMS Networks), a Swedish manufacturer of industrial communication hardware, typically found on embedded fieldbus and industrial-Ethernet connectivity modules, remote-access IIoT gateways, and industrial switches rather than end-user consumer devices.
HMS Industrial Networks AB, founded in 1988 and headquartered in Halmstad, Sweden, holds six confirmed MA-L OUI blocks in the IEEE registry. Five — 00:03:27, 00:05:94, 00:30:11, 00:30:56, and 9C:B2:06 — are registered to "HMS Industrial Networks" at the Halmstad address.
The sixth, CC:3F:1D, is registered separately to "HMS Industrial Networks SLU," the company's Spanish subsidiary based in Igualada, Barcelona. Holding six distinct OUI blocks under two related legal entities is a strong signal of a substantive, active manufacturer rather than a bare shell registration.
The product portfolio spans several brands: Anybus embedded fieldbus and industrial-Ethernet communication modules that OEMs build into their own equipment, Ewon remote-access and IIoT gateways, Intesis building-automation protocol gateways, Ixxat and PEAK System CAN/vehicle-bus interfaces, and N-Tron/Red Lion industrial switches, HMI, and controllers.
HMS maintains an active vulnerability-disclosure program. CISA has published ICS advisory ICSA-24-193-20 for CVE-2024-6558, a CVSS 6.3 flaw in the Anybus-CompactCom 30 embedded webserver, and HMS itself has issued advisories covering Anybus/InterNiche stack vulnerabilities (2022) and a Log4Shell exposure notice touching Anybus products (2021).
- IEEE assignments
- six MA-L prefixes — 00:03:27, 00:05:94, 00:30:11, 00:30:56, 9C:B2:06 (HMS Industrial Networks, Halmstad SE), CC:3F:1D (HMS Industrial Networks SLU, Igualada ES) [Confirmed] — the IEEE MA-L registry
- Registry / block size
- MA-L only (24-bit OUI); no MA-M or MA-S registrations found for HMS under any spelling searched [Confirmed] — the IEEE MA-L registry, the IEEE MA-M registry, the IEEE MA-S registry
- Primary address
- P O Box 4126, Halmstad, Halland, SE 300 04, Sweden (5 of 6 blocks; minor whitespace/formatting variance between rows is a raw-data artifact) [Confirmed] — the IEEE MA-L registry
- Secondary address
- Milà i Fontanals 7, Igualada, Barcelona, ES 08700, Spain — CC:3F:1D block only, registrant "HMS Industrial Networks SLU" [Confirmed] — the IEEE MA-L registry
- Registration dates
- Unknown for all six blocks — IEEE MA-L publishes no assignment/registration date in the source registry; none should be attributed to IEEE [Confirmed] — the IEEE MA-L registry
- Company status
- active; founded 1988, Halmstad, Sweden; ~1,100 employees; SEK 3,577M 2025 revenue; operates in 20+ countries [Confirmed] — https://www.hms-networks.com/about-us
- Device types / brands
- Anybus, Ewon, Intesis, Ixxat, PEAK System, N-Tron, Red Lion [Confirmed] — https://www.hms-networks.com/about-us
- Security context
- CVE-2024-6558 (Anybus-CompactCom 30 embedded webserver, CVSS 6.3) with CISA ICS advisory ICSA-24-193-20; HMS-published advisories for Anybus/InterNiche stack vulnerabilities (2022) and an Anybus Log4Shell exposure notice (2021)[Likely] — https://www.cisa.gov/news-events/ics-advisories/icsa-24-193-20, https://www.hms-networks.com/cybersecurity
- Ewon RCE (CVE-2026-25823)
- listed by a third-party vulnerability database, not independently cross-checked against a primary NVD/CISA record in this pass [Unknown] — https://www.sentinelone.com/vulnerability-database/cve-2026-25823/