The Slovak National Security Bureau (NBU) issued an official security alert against NERO R-ONE high-speed traffic cameras deployed as part of the country's road monitoring system, after identifying unauthorized remote-access mechanisms tied to hardcoded Russian phone numbers embedded in the devices' firmware. The finding halted the rollout of 279 units, part of a 30 million euro European Union-funded project to modernize Slovakia's traffic enforcement network.
The cameras, marketed under the NERO R-ONE branding, correspond to the CORDON PRO.M model manufactured by Semicon, a company based in St. Petersburg, Russia. According to the NBU report, the devices contain a backdoor mechanism that listens for SMS messages from a pre-configured list of Russian phone numbers. When a matching SMS is received, the device grants shell access and network access, effectively handing remote control to anyone in possession of one of those numbers.
Beyond the SMS backdoor, the NBU documented several software and hardware configuration vulnerabilities in the cameras. The devices ship with Secure Boot disabled, meaning the system does not verify firmware integrity before execution. This flaw allows attackers with physical or administrative access to install modified firmware that survives other security controls. The web management portal also features multiple vulnerabilities, and the cameras expose live video streams without requiring a password when the device's broadcast IP address is known.
The National Security Bureau began investigating the cameras after opposition politicians accused the government of purchasing equipment of Russian origin. Slovak media also reported links between the procurement and a Cyprus-based shell company that used questionable certifications as an obfuscation mechanism. The Interior Ministry initially denied that the cameras had Russian origins, arguing the equipment would be installed on a closed ministry network incapable of leaking data to the internet. Network isolation reduces exposure to the public internet, but it does not remove a backdoor embedded in the hardware. An SMS-triggered mechanism uses a cellular connection, while a compromised device can expose neighboring systems through its network connection. Network isolation reduces public internet exposure, but does not eliminate the need for firmware integrity controls and administrative safeguards.
Following the NBU's publication of its findings, ministry officials halted the rollout and declared they would commission an independent assessment. That review should determine whether the ministry can remove the backdoor, replace the firmware, or reject the cameras entirely. The case raises serious questions about supply-chain transparency in critical infrastructure, particularly when procurement involves third-party entities in offshore jurisdictions.
Traffic cameras collect more than speed readings. They capture vehicle images, license plates, road conditions, timestamps, and location data. Their network position also provides an attacker with a foothold inside transportation infrastructure. The equipment's origin matters because the procurement process appears to have obscured the original manufacturer's identity. A rebranded product makes it harder for buyers to identify the original vendor, review the software, verify code ownership, and investigate the update process.
Slovak reports link similar devices to Croatia and other Central and Eastern European countries. The available findings do not confirm the full regional scope, but neighboring governments that purchased the same model can compare hardware, firmware, and certification records. The case adds to prior incidents involving poorly secured or exposed cameras. Hunt Intelligence reported that an attacker compromised over 14,500 Dahua cameras across Ukraine and Russia by exploiting legacy vulnerabilities and a hardcoded account in some devices.
What to watch: the outcome of the independent audit promised by the Slovak Interior Ministry will be the first indicator of how deep the compromise runs and whether the cameras can be mitigated without total disposal. Any indication that the backdoor was actively exploited before discovery would make the case substantially more serious. Also watch whether other NATO and EU countries discover the same model in their traffic enforcement systems, which would indicate a broader supply-chain problem. Finally, the Slovak government's political response — particularly that of Prime Minister Robert Fico, known for his closeness to Putin — to the finding may reveal much about the degree of awareness or negligence in the procurement.
Sources: Tom's Hardware, Lavx.hu, GeekOven.net
✓ Independent sources cross-checked and verified before publishing