CVE-2020-15921

CRITICAL

Mida eFramework < 2.9.0 - Unauthenticated Backdoor Access and Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-15921. PoCs published by elbae.

AI-analyzed exploit summary This exploit generates a backdoor access code for Mida eFramework 2.9.0 by leveraging a hardcoded algorithm based on the current date and a static string. The generated code can be used to bypass authentication and reset the admin password.

Description

Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution.

Exploits (1)

exploitdb WORKING POC
by elbae · pythonwebappshardware
https://www.exploit-db.com/exploits/48823

This exploit generates a backdoor access code for Mida eFramework 2.9.0 by leveraging a hardcoded algorithm based on the current date and a static string. The generated code can be used to bypass authentication and reset the admin password.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Mida eFramework <= 2.9.0
No auth needed
Prerequisites: Network access to the target server · Target running Mida eFramework <= 2.9.0
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://elbae.github.io/jekyll/update/2020/07/14/vulns-01.html
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/159239/Mida-eFramework-2.9.0-Backdoor-Access.html

Scores

CVSS v3 9.8
EPSS 0.1829
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
midasolutions/eframework < 2.9.0
Published Jul 24, 2020
Tracked Since Feb 18, 2026