Shanghai Feixun Communication Co., Ltd. — 4 prefixes (MA-L)
Summary
- // what this is
- Shanghai Feixun Communication is registered to MAC prefix
00:6B:8Eand 3 more in the IEEE OUI database. When a device's MAC address begins with00:6B:8E, that block was registered by Shanghai Feixun Communication — the OUI identifies the maker of the network hardware, which is not always the brand on the device. Shanghai Feixun Communication has ceased operations, but the registration remains on record with IEEE. - // analyst note
- A Shanghai Feixun/PHICOMM OUI identifies genuine Feixun-designed hardware; because the vendor is defunct these devices are permanently unpatched — treat any live PHICOMM/K-series router (or Wavlink unit on the same firmware) as an unremediable-vulnerability risk, especially the UDP 21210 telnetd backdoor.
About this vendor.
Shanghai Feixun Communication Co., Ltd. (上海飞讯通信) is a Chinese networking-equipment maker that held four MA-L blocks — 00:6B:8E, F0:EB:D0, 8C:AB:8E, and D8:42:AC — all registered to the identical org name and all with Shanghai, CN addresses (postal code 201616). Internationally the company marketed under the consumer brand PHICOMM, a registered trademark of Shanghai Feixun, and its hardware spanned SOHO gear: ADSL/DSL modem-routers, Wi-Fi routers, switches, powerline (PLC) adapters, EPON/PON equipment, and USB Wi-Fi adapters, several of which carry FCC IDs under the YJY grantee prefix. The security history is the notable part of this entry. Tenable's advisory TRA-2022-01 documented a family of unpatchable vulnerabilities in PHICOMM router firmware — CVE-2022-25213/25214/25215/25217/25218/25219 — rooted in a telnetd_startup daemon listening on UDP port 21210 that implements a flawed RSA challenge/response (early firmware hardcoded the private key; a null-byte bug makes the ephemeral password predictable at roughly 1-in-94 odds), yielding a backdoor-style root shell to an attacker on the local network. A separate issue, CVE-2022-37777, is a remote command-execution flaw via the Ping function on an FIR302B A2 router. These remain unpatched because the vendor confirmed (via its German office, per Tenable) that it ceased all business worldwide as of January 1, 2019 — a collapse widely tied to the unwind of a "0-yuan purchase" (零元购) financing scheme. Some Phicomm-designed hardware was later resold under the Wavlink brand while still carrying the vulnerable firmware, so the OUI reliably flags genuine Feixun/PHICOMM silicon but the branding on a device may not.
- IEEE assignment
- 4 prefixes → Shanghai Feixun Communication Co.,Ltd., Shanghai, CN [Confirmed] — IEEE MA-L
- Registry / block size
- MA-L (24-bit OUI); exactly 4 IEEE prefixes; no MA-M or MA-S assignments found for this org [Confirmed] — IEEE the IEEE MA-L registry / the IEEE MA-M registry / the IEEE MA-S registry. NOTE: IEEE's public OUI data publishes NO assignment/registration date (the IEEE MA-L registry columns are only Registry, Assignment, Organization Name, Organization Address); any "date registered" on third-party tools is a database artifact, not an IEEE fact.
- Verified prefixes (all MA-L, Shanghai Feixun Communication Co.,Ltd.)
- 00:6B:8E, F0:EB:D0, 8C:AB:8E, D8:42:AC [Confirmed] — IEEE MA-L
- HQ / country
- Building 90, No. 4855 Guangfulin Road, Songjiang District, Shanghai, CN 201616 (registry address; block 8C:AB:8E lists an alternate No.3666 Sixian Rd., Songjiang — likely a second facility/relocation) [Confirmed] — IEEE MA-L
- Consumer brand
- PHICOMM (registered trademark of Shanghai Feixun Communication Co., Ltd.) [Confirmed] — Tenable TRA-2022-01
- Company status
- ceased all business worldwide as of 2019-01-01 (confirmed by Phicomm's German office to Tenable); collapse tied to unwind of a "0-yuan purchase" P2P-linked financing scheme [Confirmed cessation; Likely on the financing-scheme cause] — Tenable TRA-2022-01
- Device types
- SOHO/consumer networking hardware — ADSL/DSL modem-routers, Wi-Fi routers, switches, PLC (powerline) adapters, EPON/PON gear, USB Wi-Fi adapters [Confirmed] — FCC filings (YJYWR207NA, YJYWR203OC, YJYFIR300, YJYUA204SA)
- Notable security history
- Tenable TRA-2022-01 — CVE-2022-25213/25214/25215/25217/25218/25219 affecting PHICOMM K2/K3/K3C/K2G/K2P; telnetd_startup backdoor on UDP 21210 (flawed RSA challenge/response, hardcoded private key in early firmware, predictable ephemeral password ≈1-in-94); local-network root RCE, not WAN-exploitable by default; permanently unpatched. Separately CVE-2022-37777 — Ping-function RCE on FIR302B A2.[Confirmed] — Tenable TRA-2022-01, CVE details
- Related
- some Phicomm-designed hardware resold under the Wavlink brand while still running vulnerable Phicomm firmware [Likely] — Tenable TRA-2022-01
- Analyst note
- A Shanghai Feixun / PHICOMM OUI reliably identifies genuine Feixun-designed hardware, but because the vendor is defunct these devices are permanently unpatched — treat any live PHICOMM/K-series router (or Wavlink-rebranded unit on the same firmware) on a network as an unremediable-vulnerability risk, especially the UDP 21210 telnetd backdoor.