Shenzhen Sundray Technologies Company Limited — 14 prefixes (MA-L)
Summary
- // what this is
- Shenzhen Sundray Technologies is registered to MAC prefix
A8:0C:CAand 13 more in the IEEE OUI database. When a device's MAC address begins withA8:0C:CA, that block was registered by Shenzhen Sundray Technologies — the OUI identifies the maker of the network hardware, which is not always the brand on the device. - // analyst note
- A Sundray OUI on an internal network reliably flags enterprise WLAN gear worth a controller-firmware audit given the 2019 CRITICAL CVEs; randomized client MACs and re-used/spoofed OUIs mean OUI alone is not proof of device identity.
About this vendor.
Shenzhen Sundray Technologies Company Limited (深圳市信锐网科技术有限公司) is an enterprise wireless-LAN vendor founded in 2014 and headquartered in the Nanshan iPark complex on Xueyuan Road, Nanshan District, Shenzhen. It is a wholly-owned subsidiary of the Sangfor Group, and its hardware footprint spans enterprise Wi-Fi access points, wireless LAN controllers, PoE switches, gateways, and IoT networking gear sold into education, finance, healthcare, retail, government, and manufacturing. The company holds 14 IEEE MA-L (24-bit OUI) blocks, registered under the "Shenzhen Sundray Technologies company Limited" name with addresses that have drifted across the Nanshan iPark Block A1/A4 buildings over successive assignments. The most security-relevant fact for anyone classifying Sundray MACs: in April 2019 two CRITICAL-severity vulnerabilities (CVSS 9.8 each) were disclosed against the Sangfor Sundray WLAN Controller, firmware v3.7.4.2 and earlier — CVE-2019-9160, a hard-coded SSH backdoor on TCP port 22345 that yields unauthenticated root, and CVE-2019-9161, an OS command injection in nginx_webconsole.php that leaks the admin credential file. Both are remotely exploitable with no authentication. A MAC resolving to a Sundray OUI on an internal network is therefore worth flagging for controller-firmware audit. As with all OUI work, the "registration dates" shown by third-party MAC-lookup tools are database artifacts — IEEE publishes no assignment dates for MA-L blocks.
- IEEE assignment
- 14 prefixes → Shenzhen Sundray Technologies company Limited, registered Nanshan District, Shenzhen, Guangdong, CN [Confirmed] — IEEE MA-L (local cached IEEE MA-L registry)
- Registry / block size
- MA-L (24-bit OUI); 14 IEEE prefixes. No entries found in the MA-M (the IEEE MA-M registry) or MA-S (the IEEE MA-S registry) registries [Confirmed] — IEEE MA-L. NOTE: IEEE's public OUI data publishes NO assignment/registration date; any "date registered" on third-party tools (e.g. maclookup.app showing 2015-11-17 for D4:68:BA) is a database artifact, not an IEEE fact.
- Verified prefixes (all MA-L)
- A8:0C:CA, 70:3A:73, 20:20:27, 94:14:57, AC:FC:82, C8:A2:3B, 4C:EF:56, D4:68:BA, 9C:3A:9A, 18:6F:2D, 98:E3:01, 60:0A:8C, 10:2F:6E, 3C:C8:01 [Confirmed] — IEEE MA-L
- HQ / country
- Nanshan iPark, No.1001 Xueyuan Road, Nanshan District, Shenzhen, Guangdong, CN (registry addresses span Block A1/A4, postal 518055/518057) [Confirmed] — IEEE MA-L; sundray.com/about
- Company name (local)
- 深圳市信锐网科技术有限公司 [Confirmed] — sundray.com/about/index.html
- Founded
- 2014 [Confirmed] — sundray.com; sundray.com/about/index.html
- Parent company
- Sangfor Group (深信服集团) — wholly-owned subsidiary [Confirmed] — sundray.com/about/index.html; sundray.com
- Company status
- active [Confirmed] — sundray.com
- Device types
- enterprise wireless access points, wireless LAN controllers, PoE switches, gateways, IoT network equipment (primary focus enterprise WLAN infrastructure) [Confirmed] — sundray.com/product/ap.html; sundray.com
- Market segments
- enterprise networking — education, finance/banking/insurance/securities, healthcare, retail, government, manufacturing; serves 100,000+ enterprise customers across 22+ countries [Confirmed] — sundray.com/about/index.html
- Certifications
- CMMI Level 5 (2015), WAPI Alliance member (2015), SRRC, Wi-Fi Alliance enterprise certification, China MPS information-security sales license [Confirmed] — sundray.com/about/index.html
- Security context
- Two CRITICAL CVEs disclosed 2019-04-18 against Sangfor Sundray WLAN Controller firmware v3.7.4.2 and earlier — CVE-2019-9160 (CVSS 9.8, CWE-798): hard-coded backdoor SSH credentials on TCP port 22345, unauthenticated remote root; CVE-2019-9161 (CVSS 9.8, CWE-78): OS command injection via shell metacharacters in the nginx_webconsole.php Cookie header, reads admin credential config → full root compromise. Both unauthenticated and remotely exploitable. No additional NVD CVEs found for this vendor.[Confirmed] — nvd.nist.gov/vuln/detail/CVE-2019-9160; nvd.nist.gov/vuln/detail/CVE-2019-9161
- Website
- https://sundray.com/ (global); https://sundray.com.au/ (APAC) [Confirmed] — sundray.com
- Analyst note
- A Sundray OUI on an internal network reliably flags enterprise WLAN gear (APs / controllers) worth a controller-firmware audit given the 2019 CRITICAL CVEs; as with all vendors, randomized client MACs and re-used/spoofed OUIs mean OUI alone is not proof of device identity.