Particle.news

Midea PortaSplit Exposes Remote Control Without PIN

Midea says it is testing a software update to close a Bluetooth Low Energy access point that could let nearby people change settings on the device.

Overview

  • Reports first surfaced via a private tip picked up by heise.de and COMPUTER BILD that the PortaSplit may expose a previously undiscovered Bluetooth Low Energy interface.
  • The core claim is that this BLE interface can accept control commands without the usual Bluetooth pairing process or a user PIN, allowing someone nearby to operate the unit.
  • Security researcher Luis Corrons of Avast says the attack appears limited by Bluetooth proximity and would likely require an attacker to be within roughly ten meters to cause local disruptions.
  • Midea initially told reporters the issue was not reproducible but has since said it is developing and testing a firmware update and will roll it out once tests are complete.
  • Because the PortaSplit is widely sold in Germany, owners should monitor official firmware notices, keep devices physically secure, and expect a timed update from Midea to address the reported vulnerability.