Slovakia's National Security Bureau (NBU) identified multiple security vulnerabilities in 279 newly acquired NERO R-ONE speed cameras. These issues include SMS-activated backdoors and unprotected live camera feeds. The cameras were part of a traffic control system modernization effort funded by a €30 million EU budget.
The NERO R-ONE cameras are believed to be rebranded CORDON PRO.M traffic cameras, manufactured by Semicon, a St. Petersburg-based firm. The acquisition process reportedly involved a Cyprus-based shell company with fraudulent certifications. Slovakia's Ministry of the Interior has deactivated the installed cameras following these findings.
The most critical security flaw is a hardcoded list of Russian phone numbers that can trigger a backdoor via SMS, granting shell and network access. Additionally, the cameras' SecureBoot feature is ineffective, and the web management portal allows access to live streams without authentication, requiring only the device's IP address.
The discovery raises national security concerns due to potential unauthorized access to critical infrastructure. An independent auditor will verify the NBU's findings. There are also suggestions that other Eastern European countries, including Croatia, might have similar undiscovered issues with traffic cameras of comparable origin.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Slovakia's national security service, the NBU, found SMS-activated Russian backdoors and passwordless live feed access in 279 new NERO R-ONE speed cameras. These cameras, suspected to be rebranded Russian CORDON PRO.M units, were part of a €30 million EU-funded modernization project and have since been deactivated. The discovery highlights significant national security and privacy risks associated with critical infrastructure procurement.