...
...
Next Story

ECINET flaws were flagged to poll body, cyber-security agency CERT-In in July: Researcher

CERT-In recently confirmed one fix, but many critical vulnerabilities remain unresolved, raising concerns about electoral security.

Updated on: Oct 8, 2026, 06:37:26 IST
Advertisement

A security researcher has said he warned the Election Commission of India (ECI) and the country’s cyber-security agency, CERT-In, about flaws in the Commission’s voter-services website and its ECINET app back in July. He said they could expose election officials’ contact details and let attackers read or forge data in the app.

The researcher’s other findings concern the ECINET Android app, which bundles cVIGIL, the public app for reporting model-code violations, along with observer, candidate and Suvidha modules. (HT_PRINT)
The researcher’s other findings concern the ECINET Android app, which bundles cVIGIL, the public app for reporting model-code violations, along with observer, candidate and Suvidha modules. (HT_PRINT)

Three months passed with no fix acknowledged. Om Monday, a day after HT sent both agencies questions about his findings, CERT-In told him in an e-mail that one of the flaws had been fixed and that work on the rest was “under progress”. It is not clear when the fix was effected.

The researcher, Nisarga Adhikary, emailed CERT-In on July 8, with a copy to the ECI’s complaints address. CERT-In’s reply reached him on the evening of October 6.

HT sent its questions to both bodies on October 5. Neither responded.

The issue assumes significance given concerns, first flagged in an Indian Express investigation, that ECINET blocks access of Electoral Registration Officers and their deputies to the voter roll database — preventing local government officials responsible for additions and deletions in the database from effecting these changes. To be sure, none of the flaws highlighted by Adhikary were directly related to this.

The issue Adhikary rated as critical concerns a server behind the voter portal. He says it returned the names and mobile numbers of election officials to requests that carried no login, CAPTCHA or visible limit on the number of requests. The key needed to build a valid request, he says, was in the site’s public code, so the server scrambled the data without checking who was asking. It is like a counter that serves anyone who fills in the standard form without asking for identification.

He tested queries for one state and three officer-role categories, then stopped without downloading any dataset. He says the server appears to allow queries by state, district, constituency and role, which would make nationwide collection of such data feasible.

If the claims are accurate, someone with a list of officials’ names, roles and numbers could pose as a senior officer, or send targeted messages meant to steal login details. The email also lists SMS abuse and pressure on election staff as risks.

Also Read | ‘Unauthorised centralisation’: Congress leader files complaint against EC official amid electoral roll software row

Other findings

The researcher’s other findings concern the ECINET Android app, which bundles cVIGIL, the public app for reporting model-code violations, along with observer, candidate and Suvidha modules.

Adhikary says that checks that an app is talking to the genuine ECI server are disabled in some traffic, so someone on the same network, such as public Wi-Fi, could read or alter data in transit.

Encryption keys and a fixed access token are embedded in the app, where anyone who downloads it can extract them. With these, he says, two live cVIGIL endpoints returned valid responses with no individual login, which he says would let someone read or forge flying-squad and incident data.

His email to ECI and CERT called this “live-confirmed” on July 8 and said he used a non-existent location to avoid retrieving real data.

Tokens, phone numbers and, in the observer module, bank details are stored unencrypted on the app, so someone with device access, such as through malware, could take over an account.

The email alleges no theft or misuse of data. When asked which app version he analysed, where he got it and when, Adhikary told HT, “I tested the official ECINET app which was on production, google play store, 08 July 2026.” The android version app has been updated multiple times in these three months, with the latest update made on September 30.

HT also asked what his cVIGIL test returned and whether he had reason to think real citizen or incident data was reachable. He said, “I don’t remember that vulnerability because I handle a lot of security reports and this is a really old report. But an organization like ECI ignoring reports is really problematic.”

Also Read | 1.28 million cases of ‘non-mapping’, ‘logical discrepancies’ verified in Delhi SIR

CERT-In’s response

In an email to Adhikary, a screenshot of which HT has seen, CERT-In’s incident response desk said “the concerned organisation” had confirmed that one reported vulnerability, labelled “Client-Side Static Response Encryption (Hardcoded AES Key)”, was fixed. It said the rest were under progress and asked Adhikary to verify the fix and confirm.

The flaw CERT-In said was fixed is the one Adhikary rated of least concern among the issues raised in his email. He says the website’s servers scrambled their responses with a key also embedded in the site’s public code, so anyone who read the code could unscramble them. He describes it as an extra layer of protection that actually offered none, since the connection is already encrypted, and mainly serves a weakness in layered defences. He also said it amplified his more serious finding by removing an obstacle to reading the data.

The app under scrutiny

ECINET stayed in use throughout the three months. The version Adhikary examined was the one on the Google Play Store on July 8.

The poll body launched ECINET on January 22, integrating over 40 apps and web services. Announcing the platform in 2025, it said it would subsume apps including cVIGIL and Suvidha 2.0, which together had over 5.5 crore downloads, and that trials were testing cybersecurity.

On September 26, the Commission ordered a review of ECINET by a committee headed by a senior Deputy Election Commissioner, and an independent expert.

Frequently Asked Questions

What security flaws did the researcher identify?

The researcher identified flaws that could expose election officials' contact details and allow attackers to read or forge data in the ECINET app.

What actions did CERT-In take regarding the vulnerabilities?

CERT-In acknowledged a flaw was fixed and mentioned that work on the remaining vulnerabilities was 'under progress'.

What concerns were raised about the ECINET app?

Concerns raised included potential data being exposed due to inadequate app security measures and that unencrypted tokens and other sensitive information could be accessed by unauthorized users.

What was the result of the October 6 email from CERT-In to the researcher?

The email informed the researcher that one of the reported vulnerabilities had been fixed and asked him to verify this fix.
Powered ByAsk HT
 
Get the latest India News, breaking headlines, and real-time updates from across the nation. Stay informed on politics, government policies, crime, weather, and CEC Gyanesh Kumar row Live.
Get the latest India News, breaking headlines, and real-time updates from across the nation. Stay informed on politics, government policies, crime, weather, and CEC Gyanesh Kumar row Live.
SHARE THIS ARTICLE ON
Notifications

Get breaking alerts directly from the newsroom

Notifications are on!You'll be notified when news breaks