Shenzhen Four Seas Global Link Network Technology Co., Ltd. — 4 prefixes (MA-L)
Summary
- // what this is
- Shenzhen Four Seas Global Link Network Technology is registered to MAC prefix
20:0D:B0and 3 more in the IEEE OUI database. When a device's MAC address begins with20:0D:B0, that block was registered by Shenzhen Four Seas Global Link Network Technology — the OUI identifies the maker of the network hardware, which is not always the brand on the device. - // analyst note
- A COMFAST OUI on a globally-administered address = genuine COMFAST hardware. Given disclosed router CVEs and the internet-facing device class, treat such devices as candidates for firmware-version review, not inherently trusted.
About this vendor.
Shenzhen Four Seas Global Link Network Technology Co., Ltd. is the registered IEEE holder behind the COMFAST brand of consumer and SMB wireless networking gear. Founded in July 2009 and headquartered in Shenzhen, Guangdong, the company ships WiFi routers (WiFi 4/5/6, 4G/5G, MESH), indoor and outdoor access points (ceiling, in-wall, CPE, bridge), USB and PCI-E WiFi adapters, repeaters, PoE switches, and AC controllers, sold globally through Alibaba, Made-in-China, and Global Sources. It holds four MA-L (24-bit OUI) blocks. Two distinct registry addresses appear across the four: three blocks (20:0D:B0, 40:A5:EF, E0:E1:A9) carry the TAOJINDI Electronic Business Incubation Base address, while the fourth (8C:3D:16) carries a South China Digital Valley address and a slightly different org spelling ("Co.,Ltd" with no space). For asset classification this matters: a COMFAST OUI reliably flags genuine COMFAST hardware, but the device class — internet-facing SMB routers and outdoor APs — is the kind targeted by IoT botnets, and the brand has recent disclosed command-injection CVEs (CVE-2026-12814, CVE-2026-6799), so prefix presence alone is not a security posture.
- IEEE assignment
- 4 MA-L prefixes → Shenzhen Four Seas Global Link Network Technology Co., Ltd., registered Shenzhen, Guangdong, CN [Confirmed] — IEEE MA-L
- Registry / block size
- MA-L (24-bit OUI); 4 IEEE prefixes [Confirmed] — IEEE MA-L. NOTE: IEEE's public OUI data publishes NO assignment/registration date (the IEEE MA-L registry columns are only Registry, Assignment, Organization Name, Organization Address); any "date registered" on third-party tools is a database artifact, not an IEEE fact.
- HQ / country
- Shenzhen, Guangdong, CN 518000. Registry address (3 of 4 blocks): Room 607-610, Block B, TAOJINDI Electronic Business Incubation Base, Tenglong Road, Longhua District, Shenzhen, Guangdong 518000, CN [Confirmed] — IEEE MA-L
- Secondary registry address (block 8C
- 3D:16): 9/F, Block H, South China Digital Valley, No.1 South China Road, Longhua District, Shenzhen, China 518000 [Confirmed] — IEEE MA-L
- Brand / trade name
- COMFAST [Confirmed] — https://comfastgroup.com/oem/ , https://comfast.en.alibaba.com/
- Company status
- active [Likely] — https://comfastgroup.com/oem/ (vendor-stated, single primary source)
- Founded
- July 2009 [Likely] — https://comfastgroup.com/oem/ , https://comfast.en.alibaba.com/ (vendor self-reported)
- Device types
- WiFi routers (WiFi 4/5/6, 4G/5G, MESH), access points (ceiling, in-wall, outdoor/CPE/bridge), USB & PCI-E WiFi adapters, WiFi repeaters/extenders, AC controllers, PoE switches [Confirmed] — https://comfastgroup.com/oem/ , https://comfast168.en.made-in-china.com/
- Verified prefixes (all MA-L)
- 20:0D:B0, 40:A5:EF, E0:E1:A9, 8C:3D:16 [Confirmed] — IEEE MA-L; 3-block subset corroborated by https://udger.com/resources/mac-address-vendor-detail?name=shenzhen_four_seas_global_link_network_technology_co-ltd
- Certifications
- CE, FCC, RoHS [Likely] — https://comfastgroup.com/oem/ (vendor-stated)
- Chip partners
- Qualcomm, Realtek, MediaTek [Likely] — https://comfast.en.alibaba.com/ (vendor company overview, single-source)
- Security note
- Disclosed command-injection / RCE vulnerabilities in COMFAST-branded routers — CVE-2026-12814 (CF-WR631AX V3, /cgi-bin/mbox-config ping_config) and CVE-2026-6799 (CF-N1-S, /cgi-bin/mbox-config). No vendor patch was available for CVE-2026-6799 at time of publication. No COMFAST-specific botnet campaign was located, though the device class is a common IoT-botnet target. [Confirmed] — https://bitninja.com/blog/critical-server-vulnerability-in-comfast-devices/ , https://vuldb.com/vuln/372608 , https://www.sentinelone.com/vulnerability-database/cve-2026-6799/
- Market presence
- sold via Alibaba, Made-in-China, Global Sources, EC21; exhibited at Security Essen and ISC West 2025 (physical-security / surveillance networking vertical) [Confirmed] — https://comfast.en.alibaba.com/ , https://www.security-essen.de/impetus_provider/exhibitor-list/detail/shenzhen-four-seas-global-link-network-technology-co-ltd-093db
- Analyst note
- A COMFAST OUI on a globally-administered address identifies genuine COMFAST hardware; given the disclosed router CVEs and internet-facing device class, treat such devices as candidates for firmware-version review, not as inherently trusted.