Mobile Klimaanlage

Midea PortaSplit: Controllable via Bluetooth Without a PIN

According to a report by heise online, the Midea PortaSplit mobile air conditioner can be controlled by third parties via Bluetooth without any authentication. An attacker within radio range can switch the unit on and off, toggle between cooling and heating, and change the temperature – bypassing the PIN and pairing the app normally requires.

How the flaw works

The problem lies in Midea’s OEM Bluetooth SDK, which does not verify a device PIN. The control commands are AES-encrypted, but the matching keys can be calculated from information the device itself broadcasts over Bluetooth. This lets an attacker craft valid commands and take over the unit.

Important: local only, no internet access

For context: the vulnerability is limited to the Bluetooth range of around ten metres. Remote control over the internet or the cloud is explicitly not possible. An attacker would therefore have to be in the immediate vicinity of the device – for example in the neighbouring flat or outside the window.

Discovery and Midea’s response

An anonymous whistleblower reported the issue to heise in mid-August 2026; the editorial team confirmed it using a proof-of-concept app and Python scripts. Midea was initially dismissive but later acknowledged the flaw and, according to the company, is working on an OTA firmware update currently in its testing and validation phase. According to the report, all PortaSplit devices appear to be affected; no CVE has been assigned so far.

What affected owners can do now

Until a patch is available, the Bluetooth function can be disabled – though this limits the smart features. If you use the PortaSplit day to day, you will find more on operation and care in our Midea PortaSplit FAQ.


Source: heise online.

The Midea PortaSplit on Amazon:

The product display was implemented using the affiliate-toolkit WordPress plugin.
Mastodon
Scroll to Top