SECURITY Signal 446
Slovakia disables 279 EU-funded traffic cameras after finding Russian SMS backdoors and passwordless feeds
Slovakia’s national security service identified hardcoded Russian backdoors and unauthenticated live feeds in newly deployed traffic cameras, prompting a full shutdown.
This incident exposes systemic risks in supply-chain security for critical infrastructure. Engineers integrating off-the-shelf hardware must now verify firmware provenance and enforce zero-trust access controls, even for EU-funded deployments. The discovery also raises questions about due diligence in procurement processes for public-sector technology.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
279 NERO R-ONE traffic cameras contained hardcoded Russian phone numbers triggering SMS-based shell access
Live video feeds were accessible without authentication via the camera’s IP address
Slovakia deactivated the entire €30 million EU-funded system pending independent audit
THE READ
What the cluster adds up to.
Slovakia’s national security service (NBU) identified two critical vulnerabilities in 279 newly deployed traffic cameras. The first allows remote shell access via SMS messages sent from a hardcoded list of Russian phone numbers. The second exposes live video feeds to anyone with the camera’s IP address, as the web management portal lacks authentication. These flaws were discovered after the cameras were already installed, forcing the Ministry of the Interior to disable the entire system.
The cameras, marketed as NERO R-ONE, are reportedly rebranded Russian CORDON PRO.M models manufactured by Semicon in St. Petersburg. Procurement records suggest the devices were acquired through a Cyprus-based shell company, raising concerns about supply-chain transparency. The €30 million EU modernization budget allocated for this rollout is now under scrutiny, as the cameras were part of a broader infrastructure upgrade. Independent audits are planned to confirm the NBU’s findings before any remediation or replacement.
For engineers, this incident highlights the risks of integrating third-party hardware without thorough security validation. The cameras’ ineffective SecureBoot and unauthenticated web portal demonstrate how firmware-level flaws can bypass intended security controls. The SMS-triggered backdoor, in particular, suggests deliberate tampering rather than accidental misconfiguration. Organizations deploying similar systems must now account for geopolitical risks in their supply chains, even when procurement is routed through intermediaries.
The broader implications extend beyond Slovakia. Reports indicate that other Eastern European countries may have deployed similar cameras, raising the possibility of undetected backdoors in regional traffic infrastructure. The incident also underscores the challenges of balancing cost, functionality, and security in public-sector technology procurement. Engineers responsible for critical systems must now prioritize firmware audits and network segmentation to mitigate risks from compromised hardware.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗