Xiaomi Electronics — 28 prefixes (MA-L)
Summary
- // what this is
- Beijing Xiaomi Electronics is registered to MAC prefix
04:CF:8Cand 27 more in the IEEE OUI database. When a device's MAC address begins with04:CF:8C, that block was registered by Beijing Xiaomi Electronics — the OUI identifies the maker of the network hardware, which is not always the brand on the device. - // analyst note
- A globally-administered Xiaomi OUI on this block identifies genuine Xiaomi hardware; risk is data-telemetry/supply-chain, warranting elevated scrutiny in regulated networks. No network-layer OUI exploits confirmed in public threat-intel as of June 2026.
About this vendor.
The slug "vendor-xiaomi-electronics" consolidates three closely-related IEEE registry names belonging to the same Xiaomi sub-entity in Beijing: "Beijing Xiaomi Electronics Co., Ltd." (with period), "Beijing Xiaomi Electronics Co.,Ltd" (no period), and "XIAOMI Electronics,CO.,LTD" — together holding 28 MA-L (24-bit OUI) blocks. These are distinct from the larger Xiaomi group registrations such as "Xiaomi Communications Co Ltd" and "Beijing Xiaomi Mobile Software Co., Ltd," which hold their own MA-L blocks under separate vendor slugs, so treating this electronics entity as one consolidated page is more useful than minting per-prefix pages. All three name variants resolve to Beijing, China registry addresses (Xiaomi Campus / Xiaomi Building / QingHe Technology Park, Haidian District). The entity is a subsidiary of Xiaomi Corporation — the Beijing consumer-electronics maker founded in 2010 and listed on the Hong Kong Stock Exchange in 2018 — and its OUI blocks appear on consumer IoT and smart-home hardware: smartphones, tablets, routers, security cameras, smart lighting, sensors, wearables, and streaming devices. A standard OUI caveat applies: IEEE publishes no registration dates for MAC/OUI blocks, so any "first registered" date shown by third-party MAC databases (e.g. maclookup.app's 2016-04-27) is a database-ingestion artifact, not an IEEE-issued fact, and must not be recorded as an allocation date. Security context is supply-chain/telemetry-oriented rather than network-layer: Forescout's 2024 research found Xiaomi devices (categorized via this entity's OUI) present in US enterprise, government, and healthcare networks, and 20 software vulnerabilities were found and resolved via Xiaomi's HackerOne program — but no exploits are tied to the OUI assignment itself.
- IEEE assignment
- 28 MA-L prefixes → registered under three Xiaomi name variants, all in Beijing, CN [Confirmed] — IEEE MA-L registry (regauth.standards.ieee.org)
- Registry / block size
- MA-L (24-bit OUI); 28 blocks. No MA-M (28-bit) or MA-S (36-bit) blocks found for this entity [Confirmed] — IEEE the IEEE MA-L registry / the IEEE MA-M registry / the IEEE MA-S registry
- Org names (registry variants)
- "Beijing Xiaomi Electronics Co., Ltd." (period), "Beijing Xiaomi Electronics Co.,Ltd" (no period), "XIAOMI Electronics,CO.,LTD" — same sub-entity [Confirmed] — IEEE MA-L registry; Forescout OUI enumeration
- HQ / country
- Beijing, China. Registry addresses: Xiaomi Campus (CN 100085); Xiaomi Building, No.68 Qinghe Middle St, Haidian District; Building C, QingHe ShunShiJiaYe Technology Park, #66 ZhuFang Rd, Haidian District [Confirmed] — IEEE MA-L registry
- Verified sample prefixes (all MA-L)
- 04:CF:8C, 28:6C:07, 34:CE:00, 40:31:3C, 50:64:2B, 78:11:DC, 7C:49:EB, EC:41:18 [Confirmed] — maclookup.app (IEEE-sourced)
- Full 28-block set
- 047A0B, 04CF8C, 1C2AB0, 1C8BEF, 2072A9, 286C07, 34CE00, 3C2CA6, 3CBD3E, 40313C, 447147, 50642B, 68B8BB, 6C0DC4, 7811DC, 785333, 7C49EB, 8C5AF8, 94626D, B852E0, C82832, D45EEC, E0B655, E44519, E4DB6D, EC1055, EC4118, ECFA5C [Confirmed] — IEEE MA-L registry
- Parent company
- Xiaomi Corporation, Beijing — founded April 2010, listed on Hong Kong Stock Exchange July 2018; this electronics entity is one of Xiaomi's many Chinese subsidiaries [Confirmed] — ir.mi.com company profile; companydata.com; Forescout
- Company status
- active [Confirmed] — mi.com / xiaomi.com
- Device types
- consumer IoT and smart-home — smartphones (Xiaomi/Redmi/POCO), tablets, laptops, routers, security cameras, smart lighting, sensors, wearables/fitness bands, streaming boxes, air purifiers. No public prefix-to-product mapping exists [Likely] — netify.ai; mi.com; maclookup.app
- Allocation / registration date
- Unknown — IEEE publishes NO registration date for OUI/MAC assignments. Third-party tools show "first registered 2016-04-27 / updated 2018-11-16"; these are database artifacts, NOT IEEE facts, and are not recorded as allocated_date[Confirmed] — maclookup.app (artifact); IEEE the IEEE MA-L registry schema (no date column)
- Security context
- Forescout (2024) found Xiaomi devices (via this OUI) in US enterprise/government/healthcare networks; 20 software vulnerabilities found and resolved via Xiaomi HackerOne; Lithuanian NCSC raised data-privacy concerns on the Mi 10T 5G; Xiaomi publishes an ETSI EN 303 645 / OWASP-aligned IoT security baseline with BSI Kitemark. No CVEs tied to the OUI prefix itself[Confirmed] — forescout.com; oversecured.com; everphone.com; hackerone.com/xiaomi
- Analyst note
- Risk is supply-chain/telemetry (cloud data flows), not network-layer OUI exploitation. Elevated scrutiny is reasonable in regulated/government networks given Chinese origin and IoT footprint; no malware campaigns tied to Xiaomi OUI prefixes confirmed in public threat-intel as of June 2026[Likely] — forescout.com