EU-Funded Slovakia Traffic Cameras Reveal Russian Backdoors with SMS Shell Access

0
1

Key Takeaways

  • Slovakia purchased 279 NERO R-ONE speed cameras as part of a €30 million EU‑funded traffic‑control modernization project.
  • The National Security Bureau (NBU) found that the devices contain hard‑coded Russian phone numbers that enable an SMS‑activated backdoor, granting shell and network access.
  • Additional flaws include an ineffective SecureBoot implementation and a web‑management portal that streams live video to anyone who knows the camera’s IP address, requiring no authentication.
  • Investigations suggest the cameras are re‑branded Russian CORDON PRO.M units made by St. Petersburg‑based Semicon, acquired through a Cyprus‑registered shell company with falsified certifications.
  • Political pressure from Slovakia’s opposition prompted the NBU review; the ruling populist government led by Robert Fico initially dismissed the allegations, reflecting his perceived pro‑Russia stance.
  • After discovery, the cameras were deactivated pending an independent audit, and similar vulnerabilities may exist in other Eastern‑European nations that sourced comparable equipment.

Background and Acquisition
In early 2024 Slovakia embarked on a €30 million modernization of its road‑traffic monitoring infrastructure, financed largely by European Union funds. As part of this initiative the Ministry of the Interior procured 279 newly‑manufactured NERO R‑ONE speed‑camera units, intending to replace aging equipment with technology capable of automatic speed detection, license‑plate recognition, and real‑time data transmission. The purchase was presented as a straightforward upgrade aimed at improving road safety and reducing traffic‑related fatalities. However, shortly after deployment, the country’s National Security Bureau (NBU) raised alarms about the devices’ integrity, triggering a rapid reassessment of the whole program.

NBU Discovery of Security Issues
The NBU’s forensic examination revealed multiple, serious security shortcomings embedded in the NERO R‑ONE cameras. Chief among these was the presence of a hard‑coded list of Russian telephone numbers that could be used to trigger a remote backdoor via SMS. Besides this covert channel, the audit found that the cameras’ web‑based management interface was openly accessible: anyone who knew a device’s IP address could view live video streams without needing a username or password. Additionally, the SecureBoot mechanism intended to prevent unauthorized firmware execution was ineffective, allowing potentially malicious code to run on the devices. These findings collectively indicated that the cameras posed both espionage and operational risks to Slovakia’s critical infrastructure.

Technical Details of the Russian Backdoor
The backdoor operates through a pre‑programmed “trigger list” stored in the camera’s firmware. When an SMS originating from any of the listed Russian numbers is received, the device executes a command that opens a shell session and establishes a network tunnel to an external server. This tunnel can be used to exfiltrate captured imagery, alter camera settings, or deploy further malware onto the unit. Because the trigger relies solely on the sender’s phone number—a feature that cannot be changed without flashing new firmware—the vulnerability is persistent and difficult to mitigate without replacing the hardware entirely. Security experts noted that such a design is atypical for civilian traffic‑control equipment and more characteristic of surveillance gear intended for state‑controlled environments.

Live Feed Vulnerability and Ineffective SecureBoot
Beyond the SMS‑activated backdoor, the cameras exposed live video feeds through an unsecured HTTP portal. Accessing the portal required only the device’s IP address; no authentication token, HTTPS encryption, or IP‑based restriction was enforced. Consequently, anyone on the internet could locate a camera (e.g., via shodan‑style scanning) and view real‑time traffic footage, potentially enabling the tracking of police movements, identification of patrol routes, or gathering of intelligence on strategic roadways. The SecureBoot feature, which should verify the integrity of firmware before execution, was found to be either disabled or improperly configured, allowing unsigned or altered firmware to be loaded. This combination of flaws meant that an attacker could both watch the camera’s output and, via the backdoor, persistently manipulate its behavior.

Deactivation and Independent Audit
Upon confirmation of the NBU’s findings, the Slovak Ministry of the Interior ordered the immediate deactivation of all 279 NERO R-ONE units. The cameras were taken offline, and their network connections were severed to prevent any further exploitation. To ensure transparency and validate the NBU’s conclusions, the government announced that an independent third‑party auditor would conduct a thorough forensic review of the hardware, firmware, and procurement documentation. The audit aims to determine the exact extent of the vulnerabilities, assess whether any data had already been compromised, and provide recommendations for remedial actions or replacement with secure alternatives.

Possible Rebranding and Origin
Technical analysis of the camera’s internal components and firmware signatures strongly suggests that the NERO R-ONE units are re‑branded versions of the Russian CORDON PRO.M traffic‑camera system manufactured by Semicon, a firm based in St. Petersburg. The hardware layout, chipset choices, and specific firmware strings match those publicly documented for the CORDON PRO.M line. This rebranding appears to have been executed to obscure the devices’ Russian origin, allowing them to pass European procurement checks that might otherwise restrict purchases from certain jurisdictions due to security concerns.

Procurement Path via Cyprus Shell Company
Investigations traced the acquisition route to a Cyprus‑registered shell company that acted as an intermediary between the Slovak Ministry of the Interior and the actual supplier. The shell firm presented falsified certification documents claiming compliance with EU safety and cybersecurity standards. By routing the purchase through this offshore entity, the buyers attempted to bypass due‑diligence checks and obscure the true end‑user and manufacturer. The use of such intermediaries is a known tactic in procurement fraud, enabling actors to sanitize the provenance of goods that would otherwise raise red flags during vetting processes.

Political Context: Opposition Pressure and Government Denial
The NBU’s investigation was reportedly spurred by pressure from Slovakia’s opposition parties, which had long expressed skepticism about the government’s handling of EU‑funded projects and its perceived leniency toward Russia. Initially, the populist administration led by Prime Minister Robert Fico dismissed the allegations, asserting that the cameras were fully certified and posed no threat. Fico’s government has been characterized by observers as maintaining a pro‑Russia tilt, evidenced by rhetorical positions and policy choices that align more closely with Moscow than with Western European norms. The subsequent acknowledgment of the security flaws forced a reversal, though critics argue that the delay in responding heightened national risk and damaged public trust in state institutions.

Implications for Other Eastern European Countries
The Slovak case has prompted regional security analysts to scrutinize similar traffic‑control acquisitions across Eastern Europe. Several neighboring states, including Croatia, have reportedly procured camera systems from suppliers with comparable Russian links, raising the possibility that undiscovered backdoors or insecure configurations exist elsewhere. If substantiated, these vulnerabilities could compromise not only national traffic‑management capabilities but also broader security frameworks that rely on real‑time video data for law enforcement and emergency response. The episode underscores the necessity of rigorous supply‑chain vetting, independent security testing, and transparent procurement practices—especially when integrating IoT‑enabled devices into critical infrastructure.

Conclusion and Lessons Learned
The debacle surrounding Slovakia’s NERO R-ONE speed cameras serves as a stark reminder that modernization efforts must balance technological advancement with robust security safeguards. Hard‑coded backdoors, absent authentication, and defective SecureBoot mechanisms transform ostensibly benign traffic‑monitoring tools into potential vectors for espionage and sabotage. Moving forward, Slovak authorities—and their regional counterparts—should enforce strict hardware provenance verification, mandate penetration testing for all network‑connected devices, and ensure that procurement contracts include clear cybersecurity clauses and penalties for non‑compliance. Only through such measures can nations reap the benefits of smart‑city innovations without compromising their sovereign security.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here