· via Hacker News – Front Page (native)
Slovakia finds SMS-triggered Russian backdoor in national speed cameras
Slovakia's NBU says NERO R-ONE speed cameras bought for a €30 million road project hide an SMS-triggered backdoor tied to Russian phone numbers, and the deployment is now paused.

Slovakia halts camera rollout after backdoor discovery
Slovakia's national security service has told the country to stop using a high-speed traffic camera after finding a built-in backdoor that lets outsiders take control of the device, according to Risky Bulletin.
In a security alert reported by the outlet's news editor Catalin Cimpanu on August 19, 2026, the NBU warned against the NERO R-ONE speed camera. The agency's technical analysis found that the devices will hand over shell and network access whenever they receive an SMS sent from any of a set of Russian phone numbers baked into the camera's code.
A rebranded Russian camera
According to the NBU, the NERO R-ONE is a rebadged CORDON PRO.M, a model built by Semicon, a Russian company based in St. Petersburg.
That finding complicates matters for the Interior Ministry, which bought 279 of the cameras as part of a €30 million, EU-funded project to modernize Slovakia's national traffic monitoring system and was preparing to install them on selected roads.
The NBU began looking into the devices after opposition politicians accused the government of buying cameras from Russia, and after Slovak media reports tied the purchase to a Cyprus shell company that issued fake certifications.
Weaknesses beyond the backdoor
The agency's technical report describes further problems. Secure Boot is disabled, so the cameras never check where their firmware comes from. The web-based management portal contains multiple vulnerabilities. And the cameras will serve live video to anyone who knows their broadcasting IP address, without asking for a password.
The Interior Ministry had initially rejected claims that the cameras were Russian and argued that data theft was not a concern because the devices would sit on an isolated ministry network, Risky Bulletin reports. After the NBU's findings were published, ministry officials paused the deployment and said they would bring in an independent auditor to verify the results.
Units may run elsewhere
The report adds that similar devices are believed to be installed in Croatia, and possibly in other Eastern European countries as well.
Why it matters
The Slovak case is a concrete example of the risks that come with buying infrastructure hardware without knowing who built it or what is inside it. The danger here is not a software bug that happens to be exploitable, but an access path designed into the device, reachable with nothing more than a text message from the right number.
It also shows the limits of perimeter thinking. A camera that streams video to anyone with the right IP address, or that accepts commands over the cellular network, is a risk no matter how closed the network around it is claimed to be, because the exposure sits in the device itself.
Finally, the procurement trail, which local media linked to a Cyprus shell company with falsified certifications, suggests that origin and certification checks failed at multiple points despite EU funding. If comparable units are already running in Croatia and possibly beyond, other governments now have a clear reason to audit their own camera estates before those devices quietly become part of the road furniture.
- #security
- #supply-chain
- #surveillance
- #slovakia
- #firmware