What's Happening?
Slovakia's national security service, the NBU, has discovered significant security vulnerabilities in 279 new NERO R-ONE speed cameras, leading to their deactivation. These cameras, acquired as part of a €30 million EU-funded modernization project, are
suspected to be rebranded Russian CORDON PRO.M traffic cameras manufactured by St. Petersburg-based Semicon. The NBU found that the cameras contain a hardcoded list of Russian phone numbers capable of activating a backdoor via SMS, granting shell and network access. Additionally, the cameras' web management portal allows anyone with the device IP to access live streams without a password, and the SecureBoot feature is ineffective. The acquisition process was reportedly circuitous, involving a Cyprus-based shell company and fake certifications. The current Slovak government, led by Robert Fico, initially dismissed concerns about the cameras' Russian origin and security flaws, but pressure from the opposition prompted the NBU investigation. An independent auditor will now be brought in to verify the NBU's findings.
Why It's Important?
This incident highlights critical national security risks associated with foreign-sourced technology in sensitive infrastructure. The presence of SMS-activated backdoors and passwordless access in traffic cameras could allow unauthorized entities to gain control over or surveil Slovakian public spaces and data. Such vulnerabilities could be exploited for espionage, disruption of critical infrastructure, or other malicious activities, potentially compromising national security and public safety. The involvement of a shell company and fake certifications in the procurement process also raises concerns about supply chain integrity and the potential for deliberate insertion of vulnerabilities. For the U.S. and its allies, this case serves as a stark reminder of the importance of rigorous cybersecurity vetting for all imported technology, especially from nations with adversarial geopolitical interests. It underscores the need for robust procurement policies to prevent similar compromises in their own infrastructure, particularly in areas like smart cities and transportation systems that increasingly rely on interconnected devices.
What's Next?
Following the deactivation of the 279 cameras, an independent auditor will be engaged to confirm the NBU's findings regarding the Russian backdoors and other security flaws. This audit will be crucial in providing an unbiased assessment of the vulnerabilities and the extent of the potential compromise. The Slovak Ministry of the Interior will likely need to determine the future of these cameras, which could involve their permanent removal, replacement, or a costly and complex remediation effort if feasible. The investigation may also extend to the procurement process to identify and hold accountable those responsible for the acquisition of compromised equipment. Furthermore, the NBU's findings suggest that other Eastern European countries, including Croatia, might have similar issues with traffic control cameras of comparable origin, potentially triggering broader investigations and deactivations across the region. This could lead to a re-evaluation of technology procurement policies and increased scrutiny of suppliers in the EU.
Beyond the Headlines
The discovery of Russian backdoors in Slovakian traffic cameras points to a broader trend of state-sponsored cyber espionage and the weaponization of technology in critical infrastructure. This incident transcends mere cybersecurity flaws, touching upon geopolitical tensions and the subtle ways in which foreign influence can be exerted. The initial denial by the Slovak government, described as having a 'pro-Russia tilt,' suggests a potential political dimension to the issue, where national security concerns might be downplayed for political reasons. This raises ethical questions about governmental responsibility to protect national infrastructure from foreign interference, regardless of political alignment. The use of recycled plastic in a bridge in England, while seemingly unrelated, highlights a contrasting approach to technology and infrastructure development—one focused on sustainability and local benefit versus the Slovakian case which reveals a vulnerability to external manipulation. The incident underscores the need for a global re-evaluation of technology supply chains, emphasizing transparency, verifiable origins, and robust security standards to prevent critical infrastructure from becoming tools in geopolitical power struggles.











