Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout
The camera access web interface also has a no-password vulnerability.
Slovakia sought to modernize its traffic control systems with the acquisition of a batch of 279 new NERO R-ONE speed cameras, reports the Risky Bulletin Newsletter. Unfortunately, the country’s national security service, the NBU, has discovered that the cameras have multiple security issues. Firstly, they have SMS-activated Russian backdoors. Secondly, live camera feeds can be accessed by anyone with the device IP, no password necessary. Slovakia splurged a chunk of its €30 million EU-fund modernization budget on this now deactivated system.
The nearly 300 freshly installed NERO R-ONE cameras are thought to be rebranded Russian CORDON PRO.M traffic cameras, produced by a St. Petersburg-based firm called Semicon. Their path to acquisition sounds rather serpentine, with the big batch reportedly bought via a Cyprus-based shell company with fake certifications. Reports also suggest that pressure from the opposition political party in Slovakia led to the NBU investigations. The current government of the country, led by populist Robert Fico, initially denied reports that the cameras were of Russian origin and rebuffed any security concerns. Fico has what some would describe as a pro-Russia tilt, but you can read more about that elsewhere, if you are interested.
Camera flaws and vulnerabilities
As we mentioned in the intro, the hundreds of cameras Slovakia recently acquired and deployed have multiple issues which seem serious. Probably most seriously, in terms of national security, these cameras contain a hardcoded list of Russian phone numbers, which can be used to open a backdoor. An SMS from one of these numbers can open shell and network access.
Another problem with the cameras concerns broader security flaws. For example the SecureBoot feature is ineffective, and the web management portal can be accessed, exposing live streams, by anyone with the camera IP.
Cameras that have been installed and set up have since been deactivated by the Slovak Ministry of the Interior. Meanwhile, for due diligence, an independent auditor will be called in to confirm the NBU’s findings. It is thought that Croatia, and some other countries in Eastern Europe, may have undiscovered issues with traffic control cameras of similar origin.
Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.
Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.
Mark Tyson is a news editor at Tom's Hardware. He enjoys covering the full breadth of PC tech; from business and semiconductor design to products approaching the edge of reason.
-
tudos4 There is a fairly major factual error here, Slovakia did not acquire or deploy 279 of these cameras.Reply
The Slovak Interior Ministry explicitly clarified on August 7 that 279 was the number in an earlier planned procurement, but that procurement was suspended and never carried out. Under the current project, only two radar devices were purchased, and they were being used in pilot/testing operation.
So the headline saying backdoors were found in "279 new traffic cameras," and the article's statements that "nearly 300" were freshly installed and that "hundreds" had been acquired and deployed, are misleading.
The security issue itself is real. Slovakia's National Security Authority (NBÚ/SK-CERT) subsequently classified the affected systems as a significant cybersecurity threat and found undocumented remote-access mechanisms, discrepancies in communications interfaces and other serious security problems. But its published warning says the technical analysis was performed on a loaned NERO R-ONE sample, not on 279 deployed units.
Sources: https://ebs.publicnow.com/view/4C951343C31255331AEEE8F2466ED349D3BBDE7D
https://www.sk-cert.sk/sk/varovanie-pred-rizikami-cestnych-meradiel/index.html -
mhrde I would be much more interested in who performed due diligence during the initial procurement process, which Slovak local entity would have benefited from the deal, and how the respective shareholders in a Cyprus shell company are connected to government officials. I would also love to know if any payments have already been made, if there was a local service provider for maintenance, and if a security review of any further surveillance systems is underway. But thanks for clarifying that it was only in the pilot phase and everything has been stopped so that nothing will ever be seriously investigated. Very comforting.Reply -
tudos4 Reply
Yeah, I think the due-diligence question is actually the more interesting part of this.mhrde said:I would be much more interested in who performed due diligence during the initial procurement process, which Slovak local entity would have benefited from the deal, and how the respective shareholders in a Cyprus shell company are connected to government officials. I would also love to know if any payments have already been made, if there was a local service provider for maintenance, and if a security review of any further surveillance systems is underway. But thanks for clarifying that it was only in the pilot phase and everything has been stopped so that nothing will ever be seriously investigated. Very comforting.
I looked into it a bit further. The ministry's contractual supplier was Soitron. Soitron says it bought three cameras from Slovak company it-s and sold two of them to the Interior Ministry for the pilot. After the ministry ordered those two removed on August 10, Soitron says it issued a credit note and refunded the ministry. The ministry has since said Soitron will no longer work on this part of the project and announced personnel consequences internally.
The testing point is worth distinguishing too. From what I can find, the original pilot was mainly testing whether the traffic-enforcement system and transaction module worked, not conducting a serious independent security/provenance audit. It was only after concerns about the cameras' origin became public that, on August 7, the ministry asked Soitron to document their actual hardware/software origin and asked the National Security Authority (NBÚ) for an independent security assessment. That later assessment is what found the undocumented interfaces, remote-management mechanisms and other security problems.
So the correction from 279 cameras to two pilot units doesn't really make the procurement process look better. It just means the problem was caught before a large rollout rather than after one.
As for connections between the Cyprus company/shareholders and Slovak officials, I haven't found reliable evidence establishing that, so I wouldn't want to assume it. That part seems to remain an open question.
There is also now a prosecutorial review of the case, so some of the responsibility/procurement questions may eventually get a clearer answer.
Sources this time:
https://www.ta3.com/clanok/1066469/soitron-vratil-peniaze-za-radary-a-viac-ich-neosadi-odmieta-vsak-ze-ich-mohol-niekto-ovladat-na-dialku
https://spravy.stvr.sk/2026/08/generalny-prokurator-dal-preverit-nakup-skusobnych-dopravnych-radarov-ministerstvo-ich-uz-odstranilo/
https://www.uvo.gov.sk/aktualne-temy/aktualita/uvo-rozhodol-vo-veci-automatizovanych-cestnych-radarov -
passivecool ReplyYeah, I think the due-diligence question is actually the more interesting part of this.
I see this a little differently. very differently, actually. This is not a procurement failure, but a procurement success.
They wanted 300 cameras, not three million. To test and dissect at this small scale is already a lot of effort. They found the issues, paid nothing, learned lots and the entire community got a wake up call. No data was transmitted.
I would say that the road maybe could have been less bumpy, but the result was win-win-win.
We have a saying it is better to test than to study it. All the time spent in technical analysis could have been sunk into chasing shell companies - and in the end no one would have really been any wiser for it.
The slovacs i have met were all lovely people. I detest that i have to pay 35 eur to drive through the country on the highway for an hour. On Roads the EU paid to build. So i am ambivalent here. But i would break a lance and say they did a pretty good job uncovering this. -
tarasovic7 Guys,Reply
Martin from Slovakia here.
The timeline of the "Speed Cameras" story was following:
1. Goverment contract for speed cameras (we have like lower number of 10th speed cammeras in entire country now) the goal was 300 new ones.
2. First cameras has arrived and were literally certified for deployment in state from Slovensky Hydromtereologicky Institut. The state agency for measurements like speed, time distance volumes. Normally every gas station needs to be cerified from this institue to enusre that you get the exact amount of gas in car at gas station etc.) Then paper about certification was published from the Institute with sha-1 hash of the software in the cam. Then journalists were seraching for the hash on the web and found exact match with russian cams deployed in russia. Then oposition triggered alarm and state security agency NBU started to have a look what is inside the cam and then details were published.... Do you think that next round of cams with software changed in 1 bit will trigger an alarm? In state where speed cams can be installed without chceck from security agency? Country in NATO with direct borders with Ukraine. Literally russians are attempting regullary to have a watch tower in NATO and EU via slovakia via current dominant party in last 15 years. They are building infrastructure for military purpouses and everybody is somehow quiet because our national equivalent of CIA is doomed and worst in EU. This is not new. The first attempt woth cams failed but I can gurantee you there will be more attempts in the future. This was the trigger article about the story...
https://zive.aktuality.sk/clanok/cUAHtgd/slovenske-radary-spaja-s-ruskom-rovnaky-softver-prezradil-ich-odtlacok/