IndiaFocal.

India, in focus.

National

Army to Roll Out Six AASHVAST Labs for Drone Firmware Checks

The Indian Army will operate six AASHVAST labs to inspect drones, and later CCTV cameras, for firmware-level vulnerabilities and foreign-origin components.

The Indian Army is set to operate six AASHVAST laboratories across the country, where drones will undergo mandatory inspections aimed at detecting and removing firmware-level vulnerabilities. The checks are intended to ensure the unmanned aerial vehicles do not fail during operations in contested zones. CCTV cameras procured by the Army in the future are also expected to be inspected at these facilities.

AASHVAST stands for Assessment and Analysis of Electronic Systems Hardware for Vulnerabilities and Security Threats. One laboratory has already been inaugurated in Delhi, and at least five more are planned over the coming months.

The suite, described as a Firmware Analysis and Validation Suite, has been developed by QuickPay Pvt Ltd for the Directorate General of Electronics and Mechanical Engineering. It goes beyond physical inspection of drones and examines the software that runs them, allowing firmware-level flaws to be identified and eliminated.

In April this year, the Army issued a Request for Proposal to procure customised licensed software for validating firmware and embedded systems in electronic components, including UAV parts. The Army's Additional Directorate General of Public Information said in a post on August 14 that the facility, equipped with advanced capabilities, would enable evaluation of critical defence platforms and increase cyber resilience. It was described as aligned with the national vision of Atmanirbhar Bharat, strengthening operational readiness and supporting the domestic defence ecosystem.

According to Rajib Roy, Director of QuickPay Pvt Ltd, the labs are a first-of-their-kind effort to counter the common threat of enemy interference in Indian drones, which can prevent them from carrying out their designated tasks in a contested area. Until now, drones procured by the Army were not checked for firmware-level vulnerabilities, and the suite is meant to close that gap.

Firmware vulnerabilities can be introduced during manufacturing or an upgrade. They may take the form of unused code or hidden commands triggered at a particular location, which can stop a drone from completing its task. The labs can detect around 14 types of vulnerabilities, including geospatial faults that occur when flying over a certain area, problems that keep a drone from reaching its preset destination, and time- or location-specific bugs that allow normal operation except at particular moments or places.

The use of Chinese components in military drones has been a persistent concern for India, particularly because many such platforms are deployed along the eastern borders. Citing national security risks and possible data vulnerabilities, India has previously barred domestic military drone manufacturers from using Chinese-made parts. In 2025, the Army Design Bureau submitted a detailed framework to the Ministry of Defence aimed at eliminating Chinese-origin components from UAVs.

People associated with the project said the AASHVAST labs will also examine drones for Chinese and other foreign-origin active components, as well as hidden passwords, embedded keys, remote access tools and location-based security controls. One person involved in setting up the lab said this would help prevent active components sourced from China being passed off as made in India or another country merely on the basis of an invoice showing the point of purchase. There is no mechanism to determine what is embedded within the silicon, the person added, since the invoice only indicates where a part was bought and not necessarily its true origin.