MAC address vendor

Shenzhen Tenda Technology Co., Ltd. — 6 prefixes (MA-L)

Primary prefix
8C:05:28
Block
MA-L
Status
Active

Summary

// what this is
SHEN ZHEN Tenda Technology is registered to MAC prefix 8C:05:28 and 5 more in the IEEE OUI database. When a device's MAC address begins with 8C:05:28, that block was registered by SHEN ZHEN Tenda Technology — the OUI identifies the maker of the network hardware, which is not always the brand on the device.
// analyst note
Six OUI blocks plus corroborated company and product context clear the shell-abstention bar; devices identified by this vendor warrant a firmware-patch check given active CVEs.
[ 01 ] — Context

About this vendor.

Updated  ·  Confidence: High  ·  12 sources  ·  How this page is checked

A MAC address beginning with 8C:05:28, 0C:85:09, 50:DA:9E, 80:9F:E4, 8C:44:BB, or 74:DD:F0 belongs to Shenzhen Tenda Technology Co., Ltd., a Chinese networking-hardware vendor whose products typically show up as a home or SOHO Wi-Fi router, range extender, powerline adapter, or IP camera.

Tenda is a long-established consumer networking brand with global distribution and its own R&D and manufacturing operations. IEEE's MA-L registry lists six separate MA-L blocks under this exact registrant name and Shenzhen address, a pattern consistent with an active, multi-product vendor rather than a single throwaway registration.

Two other org strings in the same IEEE registry are legally distinct from this entry and must not be merged into it: a Dongguan-branch registration ("Tenda Technology Co.,Ltd.Dongguan branch") holding eleven MA-L blocks at a different address, and a separate single-OUI "Tenda Technology Co., Ltd." registration (C8:3A:35) at yet another Shenzhen address. Each is its own vendor slug.

Recent security research has flagged specific Tenda router firmware and models rather than the brand broadly. CERT/CC disclosed a hidden, unauthenticated admin backdoor (CVE-2026-11405) in /bin/httpd on multiple firmware builds in July 2026, and a separate advisory (CVE-2026-22080) found some models transmit admin credentials as reversible Base64 instead of real encryption. Independent researchers also documented eleven distinct vulnerabilities in the Tenda AC1200 W15Ev2.

Company
SHEN ZHEN TENDA TECHNOLOGY CO.,LTD [Confirmed] — IEEE MA-L registry
OUI blocks
8C:05:28, 0C:85:09, 50:DA:9E, 80:9F:E4, 8C:44:BB, 74:DD:F0 (6 MA-L blocks, one registrant) [Confirmed] — IEEE MA-L registry
Also seen on
IP cameras and mobile broadband devices [Likely] — made-in-china.com product listings
Security flag
CVE-2026-11405 (admin backdoor) and CVE-2026-22080 (credential exposure) are model/firmware-specific, not brand-wide [Confirmed] — thehackernews.com, CERT/CC-sourced advisories
Not to be confused with
Tenda Technology Co.,Ltd.Dongguan branch (11 MA-L blocks) and Tenda Technology Co., Ltd. (single OUI C8:3A:35) — separate IEEE org-string registrations [Confirmed] — IEEE MA-L registry
IEEE assignment
6 MA-L prefixes → SHEN ZHEN TENDA TECHNOLOGY CO.,LTD, registered Shenzhen, China [Confirmed] — IEEE MA-L registry. NOTE: IEEE publishes no assignment/registration date for these blocks; any third-party "date registered" is a database artifact, not an IEEE fact.
Registry / block size
MA-L (24-bit OUI) x6: 8C:05:28, 0C:85:09, 50:DA:9E, 80:9F:E4, 8C:44:BB, 74:DD:F0 [Confirmed] — IEEE MA-L registry. No MA-M (oui28/mam.csv) or MA-S (oui36/oui36.csv) block exists under any "TENDA" org string [Confirmed] — IEEE MA-M registry, the IEEE MA-S registry.
HQ / country
6-8 Floor, Tower E3, No. 1001, Zhongshanyuan Road, Nanshan District, Shenzhen, China 518052; CN [Confirmed] — IEEE MA-L registry
Company status
active [Confirmed] — tendacn.com
Device types
home/SOHO Wi-Fi routers, range extenders, powerline adapters, network switches, broadband CPE/gateways, IP cameras, mobile broadband devices [Confirmed] — tendacn.com/us/aboutus, made-in-china.com
Company substance
6 distinct MA-L blocks under one registrant/address, plus a corroborated company history and product line, clears the shell-abstention bar [Confirmed] — tendacn.com/us/aboutus, Simple Wikipedia, tendacn.com/profile
Security context
CVE-2026-11405 hidden admin backdoor in /bin/httpd on multiple Tenda firmware builds (disclosed by CERT/CC 2026-07-07, unpatched at disclosure); CVE-2026-22080 admin credentials sent as reversible Base64 on Tenda F3/N300 routers; independent research found 11 separate vulnerabilities in the AC1200 W15Ev2. Findings are scoped to specific CVEs/models, not all Tenda devices
[Confirmed] — thehackernews.com, rescana.com, socfortress.medium.com, github.com/advisories, boschko.ca
Related vendors / distinct registrations (NOT this entry)
"Tenda Technology Co.,Ltd.Dongguan branch" (Dongguan address, 11 MA-L blocks) and "Tenda Technology Co., Ltd." (single OUI C8:3A:35, different Shenzhen address) — separate IEEE org strings, separate vendor slugs if/when enriched [Confirmed] — IEEE MA-L registry, this site's own enrichment records
Analyst note
Six OUI blocks plus corroborated company and product context clear the shell-abstention bar for a real, ongoing vendor entry — but active CVEs make Tenda-identified devices worth flagging for a firmware-patch check, not just inventory classification.
[ 02 ] — OUI prefixes

Assignments by IEEE.

6
// registered prefixes6
  1. 8C:05:28MA-L
  2. 0C:85:09MA-L
  3. 50:DA:9EMA-L
  4. 80:9F:E4MA-L
  5. 8C:44:BBMA-L
  6. 74:DD:F0MA-L
[ 03 ] — Related

Keep digging.