Slovakia finds SMS backdoor in speed cameras: Russian hardware hiding behind an EU badge
When Slovakia's National Security Authority, known as NBÚ, decided to physically tear down one of the country's new speed cameras, it expected to inspect a European traffic device. Instead, analysts found hardware manufactured by Simicon of St. Petersburg, sold under a different name, and fitted with a hidden mechanism that could hand shell and network access to anyone who sent a text message from one of twelve specific Russian phone numbers. The finding has frozen a €30 million EU-funded rollout of 279 cameras and triggered a security alert covering three separate product lines across Europe.
A rebadged camera with undocumented radios
The device in question was installed as part of Slovakia's NERO R-ONE deployment, marketed by SODASUS, a Cyprus-registered supplier. When NBÚ technicians opened it up, the internals told a different story: this was a Simicon CORDON PRO.M, a product line built in St. Petersburg, Russia. According to reporting by Niebezpiecznik, the unit contained two 3G/4G cellular modems, but only one of them was documented anywhere in the product specifications or management interface. The second modem was invisible to administrators, giving whoever controlled it a silent out-of-band channel straight into the device. That kind of undocumented connectivity is precisely what supply-chain auditors look for, and precisely what rarely gets checked when procurement paperwork shows a European vendor on the invoice. The physical gap between the company that sells a device and the factory that builds it is where trust quietly erodes. The backdoor: twelve numbers and an eight-digit code
The most alarming discovery was buried in the firmware logic rather than the hardware. The camera maintained a hidden list of administrator phone numbers that never appeared in the management panel: nine mobile numbers registered in St. Petersburg, two landlines from the same city, and one mobile number from Kemerovo in Siberia. An SMS message arriving from any number on that list, followed by an eight-digit authentication code, would open remote access to the device's shell and its surrounding network. Because the trigger arrives over the cellular network via the undocumented modem, it bypasses firewalls, VPNs and every other perimeter control an operator might have configured. As Security Affairs notes, the mechanism could plausibly remain dormant for years while silently accepting commands, which makes forensic detection after the fact extremely difficult. Nobody needs to exploit a memory-corruption bug or guess a password; they only need to know the right number to text. Deployment paused and Secure Boot switched off
NBÚ's response was swift. The rollout of all 279 cameras under the EU-financed project has been paused pending inspection, and the offending units have been deactivated. The agency also disclosed two additional findings that compound the concern: Secure Boot was disabled on the devices, meaning their boot chain could not cryptographically verify that the firmware loading at startup had not been tampered with, and live video streams from the cameras were exposed without adequate protection. A camera that watches public roads is itself an intelligence asset; unauthenticated streams mean third parties could potentially view footage intended for traffic enforcement. As Tom's Hardware reports, NBÚ issued an alert covering not just the Slovak deployment but three related product lines: the SODASUS NERO R-ONE distributed from Cyprus, Simicon's own Cordon-series cameras, and Croatia's NEROline units built on the same Cordon-series platform. Any operator running equipment from these families has been effectively warned to assume compromise until proven otherwise. The supply chain lesson hiding in plain sight
This incident is a textbook case of why hardware provenance matters as much as software updates. The cameras were purchased through legitimate channels, invoiced by a European entity, and deployed with public funding. At no point did the paperwork reveal that the core product came from a manufacturer based in the country whose intelligence services European governments actively defend against. Rebadging defeats procurement screening that relies on brand names alone. For operators of any connected infrastructure, the practical takeaways are concrete. Demand full component disclosure and documented radio interfaces before purchase. Verify that boot integrity features such as Secure Boot are actually enabled, not merely available. Treat any undocumented modem, serial port or wireless interface as disqualifying until explained. And audit management panels against ground truth: if the device accepts commands that its own interface does not display, you do not fully control your own hardware. Why this matters beyond traffic enforcement
A speed camera sounds trivial next to power grids or telecom switches, but the architecture is identical: embedded Linux, cellular connectivity, persistent internet links and placement in physically accessible public locations. A compromised fleet of roadside devices offers positioning into municipal networks, a platform for surveillance of passing vehicles, or simply a demonstration that critical infrastructure can be reached at will. The €30 million question Slovakia now faces is whether any other units in the fleet contain the same hidden listeners, and whether the answer arrives before the cameras ever issue another fine. Hardware you cannot audit is hardware someone else may already control. This story reinforces a principle we keep returning to: security starts with knowing exactly what runs on the machines you depend on, a theme we explored in our guide to device security before Tor.