Skip to content

Security1 publisher3 min readPublished

Slovakia's speed cameras take orders by SMS: 279 devices, one procurement failure

The NBU says NERO R-ONE cameras bought under a 30-million-euro EU-funded project are rebadged Russian hardware carrying an SMS-triggered backdoor. The contract was the vulnerability.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Slovakia's speed cameras take orders by SMS: 279 devices, one procurement failure
Generated illustration

What happened

  • Slovakia's national security service NBU has issued a security alert against the use of NERO R-ONE high-speed traffic cameras.
  • The NBU says the cameras contain a backdoor mechanism that will execute malicious code received via an SMS from a list of hardcoded Russian phone numbers.
  • The NBU started its investigation after multiple reports in Slovak media that the cameras were bought with a no-bid direct contract from a Cyprus shell company with fake certifications.
  • According to the NBU, the cameras are a rebranded version of a Russian traffic camera model named CORDON PRO.M, produced by St. Petersburg-based Russian firm Semicon.
  • The cameras were bought as part of a 30 million euro EU-funded project to rebuild Slovakia's national traffic monitoring system.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Slovakia's national security service, the NBU, has issued a security alert against NERO R-ONE high-speed traffic cameras, saying the devices contain a backdoor that executes malicious code delivered by SMS from a list of hardcoded Russian phone numbers [1][2]. The Interior Ministry has allegedly already bought and installed 279 of them on selected roads around the country [6].

The technical finding is unpleasant, but the interesting part is how the boxes got there. According to the NBU, the cameras are a rebranded version of CORDON PRO.M, a Russian model produced by the St. Petersburg firm Semicon [4]. They were procured as part of a 30-million-euro EU-funded project to rebuild Slovakia's national traffic monitoring system [5]. The NBU opened its investigation only after Slovak media reported that the cameras had been bought through a no-bid direct contract with a Cyprus shell company holding fake certifications [3]. Nothing in that sentence is a software defect. A direct award removed competitive scrutiny, a shell company removed the manufacturer's name from the paperwork, and forged certifications removed the last document anyone was likely to check. The backdoor was the payload; the contract was the delivery mechanism.

Take the money at face value and the whole envelope works out to roughly 107,500 euros per installed camera, though the project covers more than the hardware [12]. That is the price of an acquisition process that did not establish who built the equipment.

The Ministry's first line of defence has aged badly. It initially denied the cameras were of Russian origin and said there was no danger of data theft because the devices would sit on a closed-loop Ministry network [7]. A closed loop is a defence against IP-routed access. It is not a defence against a trigger that arrives over the cellular network as a text message [2]. Air-gap reasoning fails the moment the device has its own radio, and a traffic camera fleet is defined by having one.

The rest of the NBU's technical report reads like a device that was never expected to be examined. SecureBoot is switched off, so firmware origin is never enforced [8]. The web management portal contains multiple vulnerabilities [9]. The cameras expose live streams to anyone without a password who knows the broadcasting IP address [10]. Any one of those would be enough to make the fleet untrustworthy without a nation-state anywhere near it.

Interior Ministry officials have paused the deployment and said they will order an additional assessment from an independent auditor to confirm the NBU's findings [11].

What to watch: whether that second audit is scoped to verify the backdoor or to relitigate it, and whether the 279 installed units are removed, reflashed, or quietly left in place with the SIM slots empty [6][11]. Watch also for the same hardware surfacing under other brand names elsewhere in the EU, since the rebranding through an intermediary is the part that scales [3][4]. Any buyer running a procurement process that cannot name the factory has the same exposure, whatever the certificate says.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories