Xiamen Milesight IoT Co., Ltd. — 3 prefixes (MA-L)
Summary
- // what this is
- Xiamen Milesight IoT is registered to MAC prefix
1C:C3:16and 2 more in the IEEE OUI database. When a device's MAC address begins with1C:C3:16, that block was registered by Xiamen Milesight IoT — the OUI identifies the maker of the network hardware, which is not always the brand on the device. - // analyst note
- A MAC starting 1C:C3:16, 24:E1:24, or C0:BA:1F is genuine Xiamen Milesight IoT hardware (LoRaWAN sensor/gateway, industrial cellular router, or network camera) — these are exclusive assignments, not a shared base, though no source pins a specific one of the three prefixes to a specific product model. The vendor's router, gateway, and camera lines carry a documented history of critical, sometimes-unauthenticated RCE vulnerabilities (CVE-2023-23902 CVSS 9.8; CVE-2026-32644 CVSS 9.8) and one confirmed real-world SMS-phishing abuse campaign against router firmware — treat exposed admin interfaces on these devices as a priority hardening target. No malware or trojan family is documented against these devices as of an August 2026 search.
About this vendor.
A MAC address beginning 1C:C3:16, 24:E1:24, or C0:BA:1F identifies networking or IoT hardware manufactured by Xiamen Milesight IoT Co., Ltd., a Chinese IoT and video-surveillance equipment maker. All three are exclusive IEEE MA-L blocks registered to this exact company name — not a shared IEEE base — so vendor-level identification is direct, though no source pairs a specific one of the three prefixes to a specific product line.
Milesight builds LoRaWAN sensors and gateways, industrial cellular routers, network cameras and NVRs, AIoT cameras, and asset trackers, marketed for smart agriculture, buildings, cities, logistics, and utilities deployments. The company traces to a December 2020 merger: Ursalink (IoT, founded 2017) and Milesight (video surveillance, founded 2011) became sister companies alongside Yeastar (VoIP/PBX), consolidating under the unified Milesight brand by January 2022. It is headquartered in Xiamen, Fujian, China.
Two of the three prefixes, 1C:C3:16 and 24:E1:24, carry an identical registered address that matches, digit for digit, the contact address on Milesight's own corporate brand statement; the third, C0:BA:1F, has no address on file. A separately-registered entity, "Milesight Taiwan," holds its own MA-M block at a New Taipei City address — a different registrant string, likely part of the same corporate family but unconfirmed here.
Milesight's router, gateway, and camera firmware carry a multi-year, independently NVD-verified CVE history: an unauthenticated CVSS 9.8 remote-code-execution flaw in the UR32L router (CVE-2023-23902, 2023) and a CVSS 9.8 hardcoded-key flaw in its camera line (CVE-2026-32644, 2026) are the most severe entries. Threat actors also abused an unauthenticated SMS API on these routers for a smishing campaign active from 2022 to 2025. No malware or trojan family is documented against these devices as of an August 2026 search.
- IEEE assignment
- 3 MA-L prefixes → Xiamen Milesight IoT Co., Ltd., registered Xiamen, Fujian, China [Confirmed] — the IEEE MA-L registry 1CC316, the IEEE MA-L registry 24E124, the IEEE MA-L registry C0BA1F
- Registry / block size
- MA-L (24-bit OUI); 3 exclusive IEEE MA-L blocks under this exact registrant name — not a shared/sub-allocated base [Confirmed] — the IEEE MA-L registry (three rows above); the IEEE MA-S registry and the IEEE MA-M registry carry no MA-S/MA-M match for this exact registrant name
- HQ / country
- Building C09, Software Park Phase III, Xiamen, Fujian, China 361024 (address on file for 1C:C3:16 and 24:E1:24; C0:BA:1F carries no address in its registry row) [Confirmed] — the IEEE MA-L registry 1CC316, the IEEE MA-L registry 24E124
- Company status
- active [Confirmed] — https://www.milesight.com
- Device types
- LoRaWAN sensors/gateways, industrial cellular routers, network cameras/NVRs, AIoT cameras, asset trackers, IoT displays [Confirmed] — https://www.milesight.com/iot/
- Notable products
- UG65 LoRaWAN gateway, UR32L/UR35/UR41 industrial cellular routers, SC211 4G solar-powered ANPR camera, EM300 environmental sensor [Confirmed] — https://fccid.io/2AYHY-UG65CAT1, https://fccid.io/2AYHY-SC211, https://fccid.io/2AYHY-EM300
- Verified sample prefixes (all MA-L, Xiamen Milesight IoT Co., Ltd.)
- 1C:C3:16, 24:E1:24, C0:BA:1F [Confirmed] — the IEEE MA-L registry 1CC316, the IEEE MA-L registry 24E124, the IEEE MA-L registry C0BA1F
- Corporate lineage
- Ursalink (IoT, est. 2017) and Milesight (video surveillance, est. 2011) merged December 2020 alongside Yeastar (VoIP/PBX); unified under the Milesight brand by January 2022 [Confirmed] — https://www.iotm2mcouncil.org/iot-library/news/iot-newsdesk/ursalink-merges-with-yeastar-and-milesight/, https://www.yeastar.com/news/yeastar-ursalink-milesight-merge-to-create-the-next-tech-icom/
- Related registrant (separate; not counted toward this vendor's OUI total)
- "Milesight Taiwan" holds MA-M block 10:DC:B6:50/28 at a New Taipei City, Taiwan address [Confirmed as a distinct registry row; Likely same corporate family, unconfirmed] — the IEEE MA-M registry 10DCB65
- Assignment date
- Unknown — IEEE's public OUI data publishes no assignment/registration date on any MA-L/MA-M/MA-S row [Confirmed absence of data] — the IEEE MA-L registry (header row: Registry, Assignment, Organization Name, Organization Address), https://standards.ieee.org/products-programs/regauth/
- Security history
- independently NVD-verified CVEs span 2023-2026 across three product lines — routers (CVE-2023-23902, CVSS 9.8 unauthenticated RCE; CVE-2023-43261, CVSS 7.5 credential-exposing log flaw), a LoRaWAN gateway (CVE-2025-4043, CVSS 6.8 unauthorized boot-script write), and cameras (CVE-2026-32644, CVSS 9.8 hardcoded SSL keys; CVE-2026-32649, CVSS 6.8/7.3 OS command injection) [Confirmed] — https://nvd.nist.gov/vuln/detail/CVE-2023-23902, https://nvd.nist.gov/vuln/detail/CVE-2023-43261, https://nvd.nist.gov/vuln/detail/CVE-2025-4043, https://nvd.nist.gov/vuln/detail/CVE-2026-32644, https://nvd.nist.gov/vuln/detail/CVE-2026-32649
- Real-world abuse
- threat actors abused an unauthenticated SMS inbox/outbox API on Milesight routers for a smishing campaign impersonating government, banking, postal, and telecom platforms (Sweden, Italy, Belgium), active February 2022-April 2025 [Confirmed as reported by SEKOIA/The Hacker News] — https://thehackernews.com/2025/10/hackers-exploit-milesight-routers-to.html
- Malware / trojan association
- none documented as of an August 2026 search [Confirmed as a scoped negative] — https://www.securityweek.com/milesight-industrial-router-vulnerability-possibly-exploited-in-attacks/, https://thehackernews.com/2025/10/hackers-exploit-milesight-routers-to.html
- Related vendors
- "Milesight Taiwan" (separate MA-M registrant; possibly same corporate family, unconfirmed) [Likely] — the IEEE MA-M registry 10DCB65
- Analyst note
- a MAC on 1C:C3:16, 24:E1:24, or C0:BA:1F is genuine Xiamen Milesight IoT hardware, not a shared base; given the vendor's documented critical-RCE and phishing-abuse history, treat exposed admin interfaces on these devices as a priority hardening target [Confirmed identification; Likely advisory framing] — https://nvd.nist.gov/vuln/detail/CVE-2023-23902, https://nvd.nist.gov/vuln/detail/CVE-2026-32644, https://thehackernews.com/2025/10/hackers-exploit-milesight-routers-to.html