Security1 distinct publisher3 min readUpdated
The NBU says NERO R-ONE cameras bought under a 30-million-euro EU-funded project are rebadged Russian hardware carrying an SMS-triggered backdoor. The contract was the vulnerability.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Slovakia's national security service, the NBU, has issued a security alert against NERO R-ONE high-speed traffic cameras, saying the devices contain a backdoor that executes malicious code delivered by SMS from a list of hardcoded Russian phone numbers [1][2]. The Interior Ministry has allegedly already bought and installed 279 of them on selected roads around the country [6].
The technical finding is unpleasant, but the interesting part is how the boxes got there. According to the NBU, the cameras are a rebranded version of CORDON PRO.M, a Russian model produced by the St. Petersburg firm Semicon [4]. They were procured as part of a 30-million-euro EU-funded project to rebuild Slovakia's national traffic monitoring system [5]. The NBU opened its investigation only after Slovak media reported that the cameras had been bought through a no-bid direct contract with a Cyprus shell company holding fake certifications [3]. Nothing in that sentence is a software defect. A direct award removed competitive scrutiny, a shell company removed the manufacturer's name from the paperwork, and forged certifications removed the last document anyone was likely to check. The backdoor was the payload; the contract was the delivery mechanism.
Take the money at face value and the whole envelope works out to roughly 107,500 euros per installed camera, though the project covers more than the hardware [12]. That is the price of an acquisition process that did not establish who built the equipment.
The Ministry's first line of defence has aged badly. It initially denied the cameras were of Russian origin and said there was no danger of data theft because the devices would sit on a closed-loop Ministry network [7]. A closed loop is a defence against IP-routed access. It is not a defence against a trigger that arrives over the cellular network as a text message [2]. Air-gap reasoning fails the moment the device has its own radio, and a traffic camera fleet is defined by having one.
The rest of the NBU's technical report reads like a device that was never expected to be examined. SecureBoot is switched off, so firmware origin is never enforced [8]. The web management portal contains multiple vulnerabilities [9]. The cameras expose live streams to anyone without a password who knows the broadcasting IP address [10]. Any one of those would be enough to make the fleet untrustworthy without a nation-state anywhere near it.
Interior Ministry officials have paused the deployment and said they will order an additional assessment from an independent auditor to confirm the NBU's findings [11].
What to watch: whether that second audit is scoped to verify the backdoor or to relitigate it, and whether the 279 installed units are removed, reflashed, or quietly left in place with the SIM slots empty [6][11]. Watch also for the same hardware surfacing under other brand names elsewhere in the EU, since the rebranding through an intermediary is the part that scales [3][4]. Any buyer running a procurement process that cannot name the factory has the same exposure, whatever the certificate says.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Slovakia's national security service NBU has issued a security alert against the use of NERO R-ONE high-speed traffic cameras.
The NBU says the cameras contain a backdoor mechanism that will execute malicious code received via an SMS from a list of hardcoded Russian phone numbers.
The NBU started its investigation after multiple reports in Slovak media that the cameras were bought with a no-bid direct contract from a Cyprus shell company with fake certifications.
According to the NBU, the cameras are a rebranded version of a Russian traffic camera model named CORDON PRO.M, produced by St. Petersburg-based Russian firm Semicon.
The cameras were bought as part of a 30 million euro EU-funded project to rebuild Slovakia's national traffic monitoring system.
The Interior Ministry has allegedly bought and installed 279 cameras on selected roads across Slovakia.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
State-attributed but single-source and second-hand
The core findings are attributed to a named national authority and a specific technical report, and they are unusually concrete (hardcoded numbers, SecureBoot state, unauthenticated streams). But the cluster contains exactly one publisher relaying that report rather than the report itself, there are no firmware versions, CVE identifiers or indicators, and the Interior Ministry's contrary position remains on the record pending an independent audit.
Fleet already installed, then frozen
This is not a pilot: 279 units were reportedly bought and installed on public roads under an EU-funded national programme before the alert, which is real deployment at national scale. Adoption is bounded by the fact that further rollout is now paused and the installed fleet's future depends on an independent audit.
Slightly overstated pending verification
The reporting is restrained and stays close to what the NBU said, and the deployment numbers are real, so the gap is small. It leans mildly positive because the most alarming element - remotely triggered code execution via SMS from Russian numbers - is presented as an agency finding with no evidence of exploitation in the field, no independent confirmation yet, and the operator of the fleet still disputing device origin.
Visible procurement and institutional incentives
The cluster documents concrete incentive structure: a no-bid direct award to a Cyprus shell company with fake certifications, EU money behind the programme, and an Interior Ministry that first denied Russian origin and then paused and commissioned its own confirming audit - a body with a direct interest in how the finding lands. The publishing outlet also carries a named security-vendor sponsorship, though that sponsor has no stated connection to this story.
Moderate: strong provenance, thin corroboration
Confidence is held mid-range by the combination of a credible state-agency origin and specific, internally consistent technical detail against a single relaying publisher, an unresolved dispute with the Ministry, and an independent audit that has not yet reported.
build
Slovakia's EUR 30M camera rollout shipped with an SMS backdoor and a clean paper trail1 distinct publisher
security
One hash, two countries: Slovakia's new radars run the same code as a Russian system1 distinct publisher
security
GivEnergy's administration leaves a backdoor with nobody left to patch it1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026