Shenzhen C-Data Technology Co., Ltd. — 7 prefixes (MA-L)
Summary
- // what this is
- Shenzhen C-Data Technology is registered to MAC prefix
80:F7:A6and 6 more in the IEEE OUI database. When a device's MAC address begins with80:F7:A6, that block was registered by Shenzhen C-Data Technology — the OUI identifies the maker of the network hardware, which is not always the brand on the device. - // analyst note
- C-Data OUIs identify carrier/ISP-side access equipment (OLTs/ONUs), not consumer devices. The documented CVE history for older FD11XX-series firmware is a relevant risk signal for any device inventory or vulnerability-scoring use of this vendor entry.
About this vendor.
Shenzhen C-Data Technology Co., Ltd. holds seven distinct IEEE MA-L OUI blocks — 80:F7:A6, C4:CD:50, E0:E8:E6, 50:5B:1D, D0:5F:AF, E0:67:B3, and 70:A5:6A — all registered under the identical organization string and registry address (#201, Building A4, Nanshan Zhiyuan, No.1001, Xueyuan Avenue, Changyuan Community, Taoyuan, Nanshan, Shenzhen, Guangdong, CN 518055). Founded in 2009 and headquartered in Shenzhen, C-Data is a carrier-access equipment vendor selling GPON/XGS-PON OLTs and ONUs, HFC/EOC broadband gear, managed switches, wireless access points, and OTN transport equipment to ISPs and telecom operators across 50+ countries — infrastructure hardware, not consumer end-user devices. The seven-block footprint, combined with a public product catalog, places this well above a bare single-OUI shell registration. C-Data also carries a substantive, two-sided security record: in July 2020, researchers Pierre Kim and Alexandre Torres disclosed ten CVEs (CVE-2020-29054 through CVE-2020-29063) covering hardcoded and backdoor telnet credentials across 30+ FTTH OLT models, which C-Data subsequently disputed in scope and claimed to have remediated in newer FD12XX/FD15XX/FD16XX/FD8000 firmware lines.
- IEEE assignment
- 7 MA-L prefixes → registered to "Shenzhen C-Data Technology Co., Ltd." [Confirmed] — the IEEE MA-L registry (lines 6639, 7615, 14566, 22446, 30810, 38220, 38221)
- Registry / block size
- MA-L (24-bit OUI) for all 7 blocks; no matching MA-M/MA-S entries under this org name [Confirmed] — the IEEE MA-L registry, the IEEE MA-S registry, the IEEE MA-M registry
- Registered address
- #201, Building A4, Nanshan Zhiyuan, No.1001, Xueyuan Avenue, Changyuan Community, Taoyuan, Nanshan, Shenzhen, Guangdong, CN 518055 [Confirmed] — the IEEE MA-L registry
- Company profile
- founded 2009, HQ Nanshan District, Shenzhen; ICT access-network vendor with 10+ subsidiaries/divisions operating in 50+ countries, serving telecom operators, ISPs, MSOs, and government/enterprise clients [Likely, single-source] — https://www.cdatatec.com/about-us/
- Device types
- GPON/XGS-PON OLTs and ONUs, HFC/EOC fiber-broadband access gear, wireless access equipment, managed PoE/L2 switches, OTN transport equipment [Likely, single-source vendor catalog] — https://www.cdatatec.com/products/mini-gpon-olt/, https://www.cdatatec.com/products/expandable-olt-fd1700s/
- Assignment/registration date
- Unknown — IEEE's public the IEEE MA-L registry publishes no assignment/registration date column (fields are Registry, Assignment, Organization Name, Organization Address only); this applies uniformly to all 7 blocks. A third-party lookup site shows "initially registered 30 August 2022" for 80:F7:A6, but that is a lookup-database indexing artifact, not an IEEE-published fact, and is not recorded as the registration date.[Confirmed absence of IEEE date] — https://maclookup.app/macaddress/80F7A6
- Security context
- 10 CVEs (CVE-2020-29054–CVE-2020-29063) disclosed July 2020 by Pierre Kim and Alexandre Torres, covering hardcoded/backdoor telnet credentials, cleartext/weakly-encrypted credential exposure, TFTP command injection, and pre-auth DoS across 30+ C-Data FTTH OLT models; C-Data published a rebuttal disputing exploitability/scope for some findings and claiming the hardcoded-credential issue was limited to older FD11XX-series firmware, remediated in newer FD12XX/FD15XX/FD16XX/FD8000 lines [Confirmed, two independent sources including vendor's own statement] — https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html, https://www.cdatatec.com/technical-statement.html
- Verified sample prefixes (all MA-L, Shenzhen C-Data Technology Co., Ltd.)
- 80:F7:A6, C4:CD:50, E0:E8:E6, 50:5B:1D, D0:5F:AF, E0:67:B3, 70:A5:6A [Confirmed] — the IEEE MA-L registry
- Website
- https://www.cdatatec.com [Confirmed]
- Analyst note
- C-Data OUIs identify carrier/ISP-side access equipment (OLTs/ONUs), not consumer devices; the documented CVE history is limited to older FD11XX-series firmware per the vendor's own statement, but is a relevant risk signal for any device-inventory or vulnerability-scoring use of this vendor entry.