ELSEIF
Your brief EB
178 stories from 125 feeds 523 clusters Refreshed 2 minutes ago next pull 16:53

OBSERVABILITY Signal 506

Slovakia halts deployment of traffic cameras after Russian backdoor and security flaws found

Slovakia’s national security service discovered a hardcoded Russian backdoor and multiple vulnerabilities in NERO R-ONE traffic cameras, pausing a €30 million EU-funded deployment.

WHY IT MATTERS

This incident highlights the risks of integrating untrusted hardware into critical infrastructure, even when isolated on closed networks. The backdoor and disabled security features could allow remote access or data exfiltration, undermining the integrity of traffic monitoring systems. Engineers must treat such devices as potential attack vectors, not just tools.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

The backdoor grants shell and network access via SMS from hardcoded Russian phone numbers.

02

Cameras lack SecureBoot, expose unprotected live streams, and have vulnerable web management portals.

03

Deployment was paused pending an independent audit after initial government denials of risks.

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

Slovakia’s national security service (NBU) identified a backdoor in NERO R-ONE traffic cameras, which are rebranded Russian CORDON PRO.M models. The backdoor allows remote access via SMS from a predefined list of Russian phone numbers, bypassing authentication. This mechanism is hardcoded, meaning it cannot be patched or disabled without replacing the firmware entirely. The cameras were part of a €30 million EU-funded project, raising questions about procurement oversight and supply chain security for critical infrastructure.

Beyond the backdoor, the cameras exhibit multiple security flaws. SecureBoot, a feature designed to ensure only trusted firmware runs, is disabled, leaving the devices vulnerable to firmware tampering. The web management portal contains unpatched vulnerabilities, and live video streams are accessible without authentication to anyone who knows the camera’s IP address. These issues compound the risk, as even a closed network deployment does not mitigate the potential for lateral movement or data leakage.

The Interior Ministry initially dismissed concerns, claiming the cameras posed no risk on a closed network. However, the NBU’s technical report forced a pause in deployment, with an independent audit now planned. The incident underscores the danger of assuming isolation equals security, especially when hardware originates from geopolitically adversarial sources. Similar devices may already be in use in Croatia and other Eastern European countries, suggesting a broader risk.

For engineers, this event is a case study in the limitations of network segmentation. The backdoor’s SMS-based activation could bypass perimeter defenses, and the lack of SecureBoot means firmware integrity cannot be guaranteed. The unprotected live streams further demonstrate how poorly secured devices can undermine even well-designed systems. The pause in deployment provides an opportunity to reassess procurement policies, particularly for hardware with opaque supply chains or ties to high-risk vendors.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
risky.biz via Hacker News Slovakia finds Russian backdoor in traffic speed cameras Open ↗