Skip to content

Build1 publisher3 min readPublished

Slovakia's EUR 30M camera rollout shipped with an SMS backdoor and a clean paper trail

The NBU says 279 NERO R-ONE speed cameras are rebadged Russian CORDON PRO.M units with shell access triggered by SMS from hardcoded numbers. Deployment is paused pending an independent audit.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Slovakia's national security service NBU issued a security alert against the use of NERO R-ONE high-speed traffic cameras.
  • The NBU says the cameras contain a backdoor mechanism that grants shell and network access to the devices via an SMS message received from a list of hardcoded Russian phone numbers.
  • According to the NBU, the cameras are a rebranded version of a Russian traffic camera model named CORDON PRO.M, produced by St. Petersburg-based Russian firm Semicon.
  • The cameras were bought as part of a 30 million euro EU-funded project to rebuild Slovakia's national traffic monitoring system.
  • The Interior Ministry has allegedly bought and was preparing to install 279 cameras on selected roads across Slovakia.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

Slovakia's national security service, the NBU, has issued a security alert against the NERO R-ONE high-speed traffic camera, saying the devices contain a backdoor that grants shell and network access when they receive an SMS from a list of hardcoded Russian phone numbers [1][2]. According to the NBU, the cameras are a rebranded version of CORDON PRO.M, a Russian model produced by the St. Petersburg firm Semicon [3], and they were procured under a EUR 30 million EU-funded project to rebuild the national traffic monitoring system [4].

The Interior Ministry has allegedly bought 279 cameras and was preparing to install them on selected roads [5]. That is roughly EUR 107,500 of programme budget per camera if the whole project cost is spread across the fleet, though the project covers the wider monitoring system and not cameras alone [6]. The Ministry initially denied the devices were of Russian origin and argued there was no data theft risk because they would sit on a closed-loop Ministry network [7]. A closed IP network is not a control against the mechanism the NBU describes: an SMS trigger arrives over a cellular radio, out of band from whatever routing policy the Ministry writes [8].

The rest of the NBU technical findings read like a device that was never subjected to acceptance testing. SecureBoot is turned off, so firmware origin is never enforced [9]. The web management portal contains multiple vulnerabilities [10]. The cameras expose live streams with no password to anyone who knows the broadcasting IP [11]. None of those three require a nation-state adversary or a hidden phone number to matter; the last one is a public camera feed for anyone who scans.

The origin story is the part operators should sit with. The NBU opened its investigation after the opposition accused the government of buying Russian cameras, and after Slovak media linked the purchase to a Cyprus shell company holding fake certifications [12]. So the compliance layer produced certificates, a European vendor name, and a badge on the enclosure, and none of it constrained what was inside the box. Rebadging defeats vendor-nationality screening completely, because the screen is applied to the label. What would have caught this is dull and technical: firmware signature verification as a contractual acceptance gate, a bill of materials tied to the actual silicon, an inventory of every radio in the device, and lab teardown of a sample unit before the first payment clears rather than after 279 units are in a warehouse.

The deployment is paused, and the Ministry says it will order an additional assessment from an independent auditor to confirm the NBU findings [13]. Similar devices are allegedly installed in Croatia and possibly other countries in Eastern Europe [14], which makes this a fleet question rather than a Slovak one.

Watch whether the independent audit confirms the SMS mechanism or narrows it to a vendor maintenance channel, whether the hardcoded numbers are published so other operators can check their own logs, and whether any procurement contract in the EU-funded programme actually contains a firmware-provenance clause that can be enforced now.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories