CERT-In has told the researcher who reported the vulnerabilities that one of the reported flaws has been fixed, while the remaining issues are still being worked on. The Election Commission’s ECINET platform had been flagged to India’s cybersecurity agency CERT-In months before it came under scrutiny within the poll panel, documents accessed by NDTV show.
He also reported that some certificate-checking protections could be bypassed, that certain access tokens and sensitive information were stored without encryption, and that some applications used fixed encryption values. “CERT was the organisation I could report the problems to. Another vulnerability concerned the way ECINET handled encrypted responses. Adhikary’s July report, however, contained several other findings. He alleged that parts of the ECINET mobile application contained encryption keys directly inside the app.
In an October 6 response to cybersecurity researcher Nisarga Adhikary , CERT-In said the vulnerability described as “Client-Side Static Response Encryption (Hardcoded AES Key)” had been fixed by the concerned organisation. The agency added that the other reported vulnerabilities were “under progress” and asked Adhikary to verify the fix at his end and confirm. “I reported the issue to the EC but received a boilerplate response,” Adhikary told NDTV. The researcher also said the problem could potentially be repeated across different states, districts, Assembly constituencies and officer roles. The application contained a fixed encryption key in its publicly accessible code, according to Adhikary. He said the key could be recovered from the website’s JavaScript and used to decrypt API responses. This is the vulnerability that CERT-In has now said was fixed.
During the Special Intensive Revision (SIR) of electoral rolls, Election Commissioners Sukhbir Singh Sandhu and Vivek Joshi reportedly raised concerns about aspects of the system, including access to electoral-roll databases and the way the software handled decisions that are legally assigned to election officials. Officials sought a mechanism to reverse such cases.
One issue arose in Goa, where voters initially flagged by the system for “logical discrepancies” were subsequently found eligible for inclusion.
He further reported what he described as an authentication weakness in live cVIGIL infrastructure.
Certain production endpoints accepted requests using a static token embedded in the application rather than an individual user’s login credentials, according to his report. He said he deliberately used invalid geographical information while testing so as not to retrieve real citizen or incident data.


