Build1 distinct publisher3 min readUpdated
The NBU says 279 NERO R-ONE speed cameras are rebadged Russian CORDON PRO.M units with shell access triggered by SMS from hardcoded numbers. Deployment is paused pending an independent audit.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
Slovakia's national security service, the NBU, has issued a security alert against the NERO R-ONE high-speed traffic camera, saying the devices contain a backdoor that grants shell and network access when they receive an SMS from a list of hardcoded Russian phone numbers [1][2]. According to the NBU, the cameras are a rebranded version of CORDON PRO.M, a Russian model produced by the St. Petersburg firm Semicon [3], and they were procured under a EUR 30 million EU-funded project to rebuild the national traffic monitoring system [4].
The Interior Ministry has allegedly bought 279 cameras and was preparing to install them on selected roads [5]. That is roughly EUR 107,500 of programme budget per camera if the whole project cost is spread across the fleet, though the project covers the wider monitoring system and not cameras alone [6]. The Ministry initially denied the devices were of Russian origin and argued there was no data theft risk because they would sit on a closed-loop Ministry network [7]. A closed IP network is not a control against the mechanism the NBU describes: an SMS trigger arrives over a cellular radio, out of band from whatever routing policy the Ministry writes [8].
The rest of the NBU technical findings read like a device that was never subjected to acceptance testing. SecureBoot is turned off, so firmware origin is never enforced [9]. The web management portal contains multiple vulnerabilities [10]. The cameras expose live streams with no password to anyone who knows the broadcasting IP [11]. None of those three require a nation-state adversary or a hidden phone number to matter; the last one is a public camera feed for anyone who scans.
The origin story is the part operators should sit with. The NBU opened its investigation after the opposition accused the government of buying Russian cameras, and after Slovak media linked the purchase to a Cyprus shell company holding fake certifications [12]. So the compliance layer produced certificates, a European vendor name, and a badge on the enclosure, and none of it constrained what was inside the box. Rebadging defeats vendor-nationality screening completely, because the screen is applied to the label. What would have caught this is dull and technical: firmware signature verification as a contractual acceptance gate, a bill of materials tied to the actual silicon, an inventory of every radio in the device, and lab teardown of a sample unit before the first payment clears rather than after 279 units are in a warehouse.
The deployment is paused, and the Ministry says it will order an additional assessment from an independent auditor to confirm the NBU findings [13]. Similar devices are allegedly installed in Croatia and possibly other countries in Eastern Europe [14], which makes this a fleet question rather than a Slovak one.
Watch whether the independent audit confirms the SMS mechanism or narrows it to a vendor maintenance channel, whether the hardcoded numbers are published so other operators can check their own logs, and whether any procurement contract in the EU-funded programme actually contains a firmware-provenance clause that can be enforced now.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Slovakia's national security service NBU issued a security alert against the use of NERO R-ONE high-speed traffic cameras.
The NBU says the cameras contain a backdoor mechanism that grants shell and network access to the devices via an SMS message received from a list of hardcoded Russian phone numbers.
According to the NBU, the cameras are a rebranded version of a Russian traffic camera model named CORDON PRO.M, produced by St. Petersburg-based Russian firm Semicon.
The cameras were bought as part of a 30 million euro EU-funded project to rebuild Slovakia's national traffic monitoring system.
The Interior Ministry has allegedly bought and was preparing to install 279 cameras on selected roads across Slovakia.
The Interior Ministry initially denied that the cameras were of Russian origin and said there was no danger of data theft because the devices were going to be on a closed loop Ministry network.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One publisher relaying a named state agency's alert and technical report
The substantive findings are attributed to a specific national authority's alert and technical report with concrete, falsifiable specifics: SMS trigger from hardcoded numbers, CORDON PRO.M lineage, Semicon as manufacturer, SecureBoot disabled, unauthenticated streams. That is stronger than rumour. But the cluster holds a single secondary item, no primary NBU document, no vulnerability identifiers, no vendor response, and the confirming independent audit has not happened, which caps the score well short of corroborated.
Fleet procured and staged, then arrested before confirmed installation
Adoption is real at the procurement layer: 279 units bought under a EUR 30M EU-funded programme and prepared for installation on selected roads. It is also visibly halted, with deployment paused pending an independent auditor, and the article does not establish that any camera was actually live in the field. Alleged similar installations in Croatia and elsewhere are too hedged to add weight.
Findings run slightly ahead of independent verification
The headline conclusion, a Russian SMS backdoor in EU-funded national infrastructure, is presented as settled while the only confirming step named in the story, an independent audit, is still pending and the manufacturer and reseller are unheard. The publisher does hedge the procurement count and the Croatian spillover, and the technical specifics are unusually concrete, so the overstatement is modest rather than promotional; it stems from single-sourcing a politically initiated probe, not from inflated language.
Politically initiated probe, defensive procurer, and self-commissioned audit
Nearly every actor in the chain has a stake in the outcome. The investigation was triggered by opposition accusations against the government; the Interior Ministry first denied Russian origin and asserted safety via closed-loop networking, then reversed to a pause; and the same Ministry is choosing the independent auditor that would confirm or undercut the NBU. Media reporting on a Cyprus shell company with fake certifications adds a procurement-accountability motive. None of this makes the findings wrong, but it means the record is produced by interested parties.
Moderate: credible attribution, one outlet, verification outstanding
Confidence is held mid-range by the combination of a named state agency as the source of findings, internally consistent technical detail, and a concrete operator action on the one hand, against single-publisher sourcing, hedged procurement figures, absent vendor voice, unverified regional spillover, and a pending audit on the other.
security
Slovakia's speed cameras take orders by SMS: 279 devices, one procurement failure1 distinct publisher
security
One hash, two countries: Slovakia's new radars run the same code as a Russian system1 distinct publisher
security
Windows 11's secure kernel trusts a RAM chip that never checks who is writing to it1 distinct publisher
security
Microsoft is investigating whether its own August Patch Tuesday build breaks apps on Windows 111 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026