Wuxi Xinjie Electric Co., Ltd — B8:A7:5E (MA-L)
Summary
- // what this is
- Wuxi Xinjie Electric is registered to MAC prefix
B8:A7:5Ein the IEEE OUI database. When a device's MAC address begins withB8:A7:5E, that block was registered by Wuxi Xinjie Electric — the OUI identifies the maker of the network hardware, which is not always the brand on the device. - // analyst note
- B8:A7:5E on a network = an Xinje industrial device (PLC/HMI/IoT gateway/EtherCAT controller), typically OT. Presence in an IT-only segment warrants investigation. Given the disclosed chained RCE (CVE-2021-34605 + CVE-2021-34606, CVSS 7.3 HIGH, no confirmed patch) in the XD/E programming tool, assess any engineering workstation connected to Xinje PLCs; segment these devices and keep them off the public internet.
About this vendor.
The prefix B8:A7:5E resolves to Wuxi Xinjie Electric Co., Ltd, an industrial automation manufacturer in the Hu Tai Industrial Park, Binhu District, Wuxi, Jiangsu, China. The company self-brands in English as "Xinje" (en.xinje.com); "Xinjie" is an alternate romanisation that surfaces in some third-party MAC registries and in the IEEE record itself, so both spellings point at the same registrant. This is a single MA-L allocation (~16.7M addresses), not a consolidated multi-block vendor. What matters operationally is what the hardware is: Xinje builds OT/ICS equipment — programmable logic controllers (PLC), human-machine interface (HMI) panels, servo drives, frequency inverters, motion controllers, IoT gateways, and EtherCAT switches and slave devices — so a B8:A7:5E address on a network almost certainly belongs to an industrial controller, not a consumer device, and its appearance in an IT-only segment warrants a look. The company is an EtherCAT Technology Group member and ships Ethernet/Modbus-TCP add-on modules for its XC/XD PLC families. There is a material security caveat: CISA advisory ICSA-23-024-01 (24 Jan 2026 [year per advisory page; original 2023]) documents two chained, locally/network-adjacent vulnerabilities in the XINJE XD/E Series PLC Program Tool (v3.5.1 and prior) — CVE-2021-34605 (zip-slip path traversal) and CVE-2021-34606 (DLL search-path hijack), each CVSS v3.1 7.3 (HIGH) — which together allow arbitrary code execution on an engineering workstation that opens a malicious project file or syncs from a compromised PLC. No vendor patch was publicly confirmed at advisory time, so any workstation that programs Xinje PLCs should be assessed for exposure, and the devices kept network-segmented and off the public internet.
- IEEE assignment
- B8:A7:5E → Wuxi Xinjie Electric Co.,Ltd (registrant spelling "Xinjie"; company self-brands "Xinje") [Confirmed] — IEEE MA-L (line 104); corroborated maclookup.app, udger.com
- Registry / block size
- MA-L (24-bit OUI; ~16.7M addresses); single block [Confirmed] — IEEE MA-L / maclookup.app
- HQ / country
- No. 9 Liu Tang Road, Hu Tai Industrial Park, Binhu District, Wuxi, Jiangsu 320200, CN [Confirmed] — IEEE MA-L (line 104), udger.com
- Registration date
- Unknown — IEEE publishes NO assignment/registration date (the IEEE MA-L registry columns are only Registry, Assignment, Organization Name, Organization Address). A third-party tool (maclookup.app) shows "April 2023" but that is a database artifact, not an IEEE fact. [Unknown] — see no_ieee_date_note
- Company status
- active — current website, ~300+ distributor network across 16+ countries, active EtherCAT Technology Group membership [Confirmed] — en.xinje.com, ethercat.org members list
- Device types
- PLC, HMI panels, servo drives, frequency inverters, motion controllers, IoT gateways / IoT touch screens, EtherCAT switches & slave devices, Ethernet communication modules, machine vision [Confirmed] — en.xinje.com, ethercat.org
- Networking / protocols
- EtherCAT (ETG member), Modbus TCP, Ethernet/IP; Ethernet add-on modules sold for XC/XD PLC series; "Industrial Internet" line with IoT gateways + cloud connectivity [Confirmed] — ethercat.org, en.xinje.com, lollette.com (XC/XD Ethernet module)
- Industry verticals
- industrial automation broadly — fastener manufacturing, textile machinery, coal mining, HVAC/central air conditioning, general OT/ICS [Confirmed] — ethercat.org, en.xinje.com
- Security note
- CISA ICSA-23-024-01 covers CVE-2021-34605 (zip-slip path traversal, CWE-23, CVSS v3.1 7.3 HIGH) and CVE-2021-34606 (uncontrolled search-path / DLL hijack, CVSS v3.1 7.3 HIGH) in the XINJE XD/E Series PLC Program Tool ≤ v3.5.1 — chained to achieve arbitrary code execution via a malicious project file or a compromised PLC. Disclosed by Claroty Team82 (May 2022, extended coordinated disclosure); no vendor patch publicly confirmed at advisory time.[Confirmed] — cisa.gov ICSA-23-024-01, claroty.com Team82, nvd.nist.gov CVE-2021-34605
- Name disambiguation
- B8:A7:5E is Wuxi Xinjie/Xinje Electric. NOT the same as "SHENZHEN JIAXINJIE ELECTRON CO.,LTD" (E0:3C:5B, MA-L) or "Suzhou Ruixinjie Information Technology Co.,Ltd" (MA-M, 50:62:55:5x) — different companies that merely share the "xinjie" syllable.[Confirmed] — IEEE the IEEE MA-L registry / the IEEE MA-M registry
- Analyst note
- A B8:A7:5E MAC indicates an Xinje industrial device — most likely a PLC, HMI, IoT gateway, or EtherCAT controller in an OT environment. Presence in an IT/enterprise-only segment warrants investigation. Given the disclosed chained RCE in the XD/E programming tool with no confirmed patch, any engineering workstation connected to Xinje PLCs should be assessed; these devices should be segmented and never internet-facing.