
After Nisarga Adhikary exposed a hardcoded AES key flaw on July 8, CERT‑In confirmed the fix by October 6. The Election Commission’s ECINET platform, which aggregates more than 40 election‑related apps, now has that specific vulnerability closed. However, several other critical weaknesses remain under investigation.
Adhikary’s report detailed that a live ECINET API could return personal data of election officials without authentication, including names, mobile numbers and designations. He also exposed that the mobile app stored encryption keys internally, allowing attackers to decrypt responses. Additionally, certificate‑checking protections could be bypassed, and access tokens were stored in plaintext. One static token used in production endpoints let requests bypass user credentials entirely.
The EC’s launch in January sparked earlier concerns. Chief Election Commissioner Gyanesh Kumar, Sukhbir Singh Sandhu and Vivek Joshi raised objections during the Special Intensive Revision, citing unauthorized changes to Form 6 and the system’s handling of "logical discrepancies". Sandhu called the changes illegal, prompting the Commission to announce an independent review.
In Goa, a voter flagged by ECINET as having a "logical discrepancy" was later cleared and allowed to vote, highlighting the system’s flaws. Local officials now demand a rollback of automated decisions pending the review.
CERT‑In is working on the remaining ECINET issues, with a projected completion by the end of November. The Commission’s review committee, headed by a Senior Deputy Election Commissioner and an IIT/IIIT tech expert, will report its findings before the next general election.