MAC address vendor

Shenzhen Four Seas Global Link Network Technology Co., Ltd. — 4 prefixes (MA-L)

Primary prefix
20:0D:B0
Block
MA-L
Status
Active

Summary

// what this is
Shenzhen Four Seas Global Link Network Technology is registered to MAC prefix 20:0D:B0 and 3 more in the IEEE OUI database. When a device's MAC address begins with 20:0D:B0, that block was registered by Shenzhen Four Seas Global Link Network Technology — the OUI identifies the maker of the network hardware, which is not always the brand on the device.
// analyst note
A COMFAST OUI on a globally-administered address = genuine COMFAST hardware. Given disclosed router CVEs and the internet-facing device class, treat such devices as candidates for firmware-version review, not inherently trusted.
[ 01 ] — Context

About this vendor.

Updated  ·  Confidence: High

Shenzhen Four Seas Global Link Network Technology Co., Ltd. is the registered IEEE holder behind the COMFAST brand of consumer and SMB wireless networking gear. Founded in July 2009 and headquartered in Shenzhen, Guangdong, the company ships WiFi routers (WiFi 4/5/6, 4G/5G, MESH), indoor and outdoor access points (ceiling, in-wall, CPE, bridge), USB and PCI-E WiFi adapters, repeaters, PoE switches, and AC controllers, sold globally through Alibaba, Made-in-China, and Global Sources. It holds four MA-L (24-bit OUI) blocks. Two distinct registry addresses appear across the four: three blocks (20:0D:B0, 40:A5:EF, E0:E1:A9) carry the TAOJINDI Electronic Business Incubation Base address, while the fourth (8C:3D:16) carries a South China Digital Valley address and a slightly different org spelling ("Co.,Ltd" with no space). For asset classification this matters: a COMFAST OUI reliably flags genuine COMFAST hardware, but the device class — internet-facing SMB routers and outdoor APs — is the kind targeted by IoT botnets, and the brand has recent disclosed command-injection CVEs (CVE-2026-12814, CVE-2026-6799), so prefix presence alone is not a security posture.

IEEE assignment
4 MA-L prefixes → Shenzhen Four Seas Global Link Network Technology Co., Ltd., registered Shenzhen, Guangdong, CN [Confirmed] — IEEE MA-L
Registry / block size
MA-L (24-bit OUI); 4 IEEE prefixes [Confirmed] — IEEE MA-L. NOTE: IEEE's public OUI data publishes NO assignment/registration date (the IEEE MA-L registry columns are only Registry, Assignment, Organization Name, Organization Address); any "date registered" on third-party tools is a database artifact, not an IEEE fact.
HQ / country
Shenzhen, Guangdong, CN 518000. Registry address (3 of 4 blocks): Room 607-610, Block B, TAOJINDI Electronic Business Incubation Base, Tenglong Road, Longhua District, Shenzhen, Guangdong 518000, CN [Confirmed] — IEEE MA-L
Secondary registry address (block 8C
3D:16): 9/F, Block H, South China Digital Valley, No.1 South China Road, Longhua District, Shenzhen, China 518000 [Confirmed] — IEEE MA-L
Brand / trade name
COMFAST [Confirmed] — https://comfastgroup.com/oem/ , https://comfast.en.alibaba.com/
Company status
active [Likely] — https://comfastgroup.com/oem/ (vendor-stated, single primary source)
Founded
July 2009 [Likely] — https://comfastgroup.com/oem/ , https://comfast.en.alibaba.com/ (vendor self-reported)
Device types
WiFi routers (WiFi 4/5/6, 4G/5G, MESH), access points (ceiling, in-wall, outdoor/CPE/bridge), USB & PCI-E WiFi adapters, WiFi repeaters/extenders, AC controllers, PoE switches [Confirmed] — https://comfastgroup.com/oem/ , https://comfast168.en.made-in-china.com/
Verified prefixes (all MA-L)
20:0D:B0, 40:A5:EF, E0:E1:A9, 8C:3D:16 [Confirmed] — IEEE MA-L; 3-block subset corroborated by https://udger.com/resources/mac-address-vendor-detail?name=shenzhen_four_seas_global_link_network_technology_co-ltd
Certifications
CE, FCC, RoHS [Likely] — https://comfastgroup.com/oem/ (vendor-stated)
Chip partners
Qualcomm, Realtek, MediaTek [Likely] — https://comfast.en.alibaba.com/ (vendor company overview, single-source)
Security note
Disclosed command-injection / RCE vulnerabilities in COMFAST-branded routers — CVE-2026-12814 (CF-WR631AX V3, /cgi-bin/mbox-config ping_config) and CVE-2026-6799 (CF-N1-S, /cgi-bin/mbox-config). No vendor patch was available for CVE-2026-6799 at time of publication. No COMFAST-specific botnet campaign was located, though the device class is a common IoT-botnet target. [Confirmed] — https://bitninja.com/blog/critical-server-vulnerability-in-comfast-devices/ , https://vuldb.com/vuln/372608 , https://www.sentinelone.com/vulnerability-database/cve-2026-6799/
Market presence
sold via Alibaba, Made-in-China, Global Sources, EC21; exhibited at Security Essen and ISC West 2025 (physical-security / surveillance networking vertical) [Confirmed] — https://comfast.en.alibaba.com/ , https://www.security-essen.de/impetus_provider/exhibitor-list/detail/shenzhen-four-seas-global-link-network-technology-co-ltd-093db
Analyst note
A COMFAST OUI on a globally-administered address identifies genuine COMFAST hardware; given the disclosed router CVEs and internet-facing device class, treat such devices as candidates for firmware-version review, not as inherently trusted.
[ 02 ] — OUI prefixes

Assignments by IEEE.

4
// registered prefixes4
  1. 20:0D:B0MA-L
  2. 40:A5:EFMA-L
  3. E0:E1:A9MA-L
  4. 8C:3D:16MA-L
[ 03 ] — Related

Keep digging.