Skip to content
Tech News
← Back to articles

Slovakia discovers Russian backdoors in 279 new traffic cameras — SMS-triggered shell access and passwordless live feeds found in EU-funded rollout

read original more articles
Why This Matters

The discovery of security vulnerabilities in Slovakia's new traffic cameras highlights the risks of deploying IoT devices with inadequate security measures, especially when sourced from potentially malicious or unverified suppliers. This incident underscores the importance for governments and consumers to scrutinize device origins and security features to prevent espionage and data breaches. It also emphasizes the need for stricter oversight and security standards in the rollout of critical infrastructure technology.

Key Takeaways

Slovakia sought to modernize its traffic control systems with the acquisition of a batch of 279 new NERO R-ONE speed cameras, reports the Risky Bulletin Newsletter. Unfortunately, the country’s national security service, the NBU, has discovered that the cameras have multiple security issues. Firstly, they have SMS-activated Russian backdoors. Secondly, live camera feeds can be accessed by anyone with the device IP, no password necessary. Slovakia splurged a chunk of its €30 million EU-fund modernization budget on this now deactivated system.

The nearly 300 freshly installed NERO R-ONE cameras are thought to be rebranded Russian CORDON PRO.M traffic cameras, produced by a St. Petersburg-based firm called Semicon. Their path to acquisition sounds rather serpentine, with the big batch reportedly bought via a Cyprus-based shell company with fake certifications. Reports also suggest that pressure from the opposition political party in Slovakia led to the NBU investigations. The current government of the country, led by populist Robert Fico, initially denied reports that the cameras were of Russian origin and rebuffed any security concerns. Fico has what some would describe as a pro-Russia tilt, but you can read more about that elsewhere, if you are interested.

Camera flaws and vulnerabilities

As we mentioned in the intro, the hundreds of cameras Slovakia recently acquired and deployed have multiple issues which seem serious. Probably most seriously, in terms of national security, these cameras contain a hardcoded list of Russian phone numbers, which can be used to open a backdoor. An SMS from one of these numbers can open shell and network access.

Latest Videos From Tom's Hardware Watch full video here:

Another problem with the cameras concerns broader security flaws. For example the SecureBoot feature is ineffective, and the web management portal can be accessed, exposing live streams, by anyone with the camera IP.

Cameras that have been installed and set up have since been deactivated by the Slovak Ministry of the Interior. Meanwhile, for due diligence, an independent auditor will be called in to confirm the NBU’s findings. It is thought that Croatia, and some other countries in Eastern Europe, may have undiscovered issues with traffic control cameras of similar origin.

Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.