Do you have an authoritative reference to back your claim that the MAC address
assigned to a device by the manufacturer is only "pseudo unique"?
Spoofing a MAC address does not require knowing the address. Given that the MAC
address consists of a limited set of characters, a simple brute-force method
would suffice to get through a MAC filter. And, given that you've probably got
several MAC addresses included in your security definition, the likelyhood of
hitting a valid address is increased.