ECINET flaws were flagged to poll body, cyber-security agency CERT-In in July: Researcher
CERT-In recently confirmed one fix, but many critical vulnerabilities remain unresolved, raising concerns about electoral security.
A security researcher has said he warned the Election Commission of India (ECI) and the country’s cyber-security agency, CERT-In, about flaws in the Commission’s voter-services website and its ECINET app back in July. He said they could expose election officials’ contact details and let attackers read or forge data in the app.

Three months passed with no fix acknowledged. Om Monday, a day after HT sent both agencies questions about his findings, CERT-In told him in an e-mail that one of the flaws had been fixed and that work on the rest was “under progress”. It is not clear when the fix was effected.
The researcher, Nisarga Adhikary, emailed CERT-In on July 8, with a copy to the ECI’s complaints address. CERT-In’s reply reached him on the evening of October 6.
HT sent its questions to both bodies on October 5. Neither responded.
The issue assumes significance given concerns, first flagged in an Indian Express investigation, that ECINET blocks access of Electoral Registration Officers and their deputies to the voter roll database — preventing local government officials responsible for additions and deletions in the database from effecting these changes. To be sure, none of the flaws highlighted by Adhikary were directly related to this.
Also Read | ‘Who modified Form 6?’: SC seeks record from EC over voter form changes
What was flagged
The issue Adhikary rated as critical concerns a server behind the voter portal. He says it returned the names and mobile numbers of election officials to requests that carried no login, CAPTCHA or visible limit on the number of requests. The key needed to build a valid request, he says, was in the site’s public code, so the server scrambled the data without checking who was asking. It is like a counter that serves anyone who fills in the standard form without asking for identification.
He tested queries for one state and three officer-role categories, then stopped without downloading any dataset. He says the server appears to allow queries by state, district, constituency and role, which would make nationwide collection of such data feasible.
If the claims are accurate, someone with a list of officials’ names, roles and numbers could pose as a senior officer, or send targeted messages meant to steal login details. The email also lists SMS abuse and pressure on election staff as risks.
Other findings
The researcher’s other findings concern the ECINET Android app, which bundles cVIGIL, the public app for reporting model-code violations, along with observer, candidate and Suvidha modules.
Adhikary says that checks that an app is talking to the genuine ECI server are disabled in some traffic, so someone on the same network, such as public Wi-Fi, could read or alter data in transit.
Encryption keys and a fixed access token are embedded in the app, where anyone who downloads it can extract them. With these, he says, two live cVIGIL endpoints returned valid responses with no individual login, which he says would let someone read or forge flying-squad and incident data.
His email to ECI and CERT called this “live-confirmed” on July 8 and said he used a non-existent location to avoid retrieving real data.
Tokens, phone numbers and, in the observer module, bank details are stored unencrypted on the app, so someone with device access, such as through malware, could take over an account.
The email alleges no theft or misuse of data. When asked which app version he analysed, where he got it and when, Adhikary told HT, “I tested the official ECINET app which was on production, google play store, 08 July 2026.” The android version app has been updated multiple times in these three months, with the latest update made on September 30.
HT also asked what his cVIGIL test returned and whether he had reason to think real citizen or incident data was reachable. He said, “I don’t remember that vulnerability because I handle a lot of security reports and this is a really old report. But an organization like ECI ignoring reports is really problematic.”
Also Read | 1.28 million cases of ‘non-mapping’, ‘logical discrepancies’ verified in Delhi SIR
CERT-In’s response
In an email to Adhikary, a screenshot of which HT has seen, CERT-In’s incident response desk said “the concerned organisation” had confirmed that one reported vulnerability, labelled “Client-Side Static Response Encryption (Hardcoded AES Key)”, was fixed. It said the rest were under progress and asked Adhikary to verify the fix and confirm.
The flaw CERT-In said was fixed is the one Adhikary rated of least concern among the issues raised in his email. He says the website’s servers scrambled their responses with a key also embedded in the site’s public code, so anyone who read the code could unscramble them. He describes it as an extra layer of protection that actually offered none, since the connection is already encrypted, and mainly serves a weakness in layered defences. He also said it amplified his more serious finding by removing an obstacle to reading the data.
The app under scrutiny
ECINET stayed in use throughout the three months. The version Adhikary examined was the one on the Google Play Store on July 8.
The poll body launched ECINET on January 22, integrating over 40 apps and web services. Announcing the platform in 2025, it said it would subsume apps including cVIGIL and Suvidha 2.0, which together had over 5.5 crore downloads, and that trials were testing cybersecurity.
On September 26, the Commission ordered a review of ECINET by a committee headed by a senior Deputy Election Commissioner, and an independent expert.

E-Paper

