Slovakia discovers Russian backdoor in NERO R-ONE speedometers
The Interior Ministry initially denied that the cameras were of Russian origin.

Image by Cybernews.
- Slovakia’s security authority found Russian-linked backdoor functions in NERO R-ONE speed cameras.
- The cameras can reportedly receive SMS commands from Russian numbers and allow full remote control.
- The devices were bought through a no-bid deal with Sodasus, a Cyprus shell company with fake certifications.
- Deployment is paused, while opposition lawmakers demand Interior Minister Matúš Šutaj Eštok be replaced.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Given Slovak Prime Minister Robert Fico’s accommodating stance toward Vladimir Putin’s Russia, the discovery of multiple Russian backdoors embedded in the country’s speed cameras should prove embarrassing for his government. He’s not fussed, though.
An assessment by the National Security Authority (NBU), Slovakia’s cybersecurity watchdog, found an undocumented module linked to 12 Russian telephone numbers inside the devices. These are NERO R-ONE high-speed traffic cameras.
According to NBU, this is a backdoor mechanism that could execute malicious code received via an SMS from a list of the aforementioned Russian numbers.
That, along with a password, is enough to give an operator full remote control of a camera, said Peter Bator, a cybersecurity expert, adding that the numbers came from the St. Petersburg and Kemerovo regions.
Check if your data has been leaked
NBU started an investigation into the devices after multiple reports in Slovak media that the cameras were purchased with a no-bid direct deal with Sodasus, a Cyprus shell company with fake certifications.
Progressive Slovakia, a party working in the opposition, then obtained NBU’s assessment through a freedom-of-information request.
It turns out that NBU conducted a security analysis of a NERO R-ONE speed camera and identified several security risks. They include:
- The true origin of the camera’s hardware and software
- Inconsistency between the documented and detected configuration of the product's communication interfaces
- Pre-configured remote access and product management mechanisms, the configuration of which is not fully available to the user
- Inconsistency between the declared and actual measurement processing software
- Poor software security
The Slovak Interior Ministry initially denied that the cameras were of Russian origin and claimed there was no risk of data theft. But Bator, the cybersecurity expert, is adamant that the risk is huge.
This is a completely concrete example of how Russia uses technology that it sells for spying,Peter Bator, a cybersecurity expert, told local media.
Additionally, NBU’s technical report says that the cameras are a rebranded version of a Russian speed camera model – the Cordon.Pro.M produced in St. Petersburg – and are simply very insecure.
The analysis has shown that the web management portal contains multiple vulnerabilities, and the devices expose live streams to anyone without a password who knows their broadcasting IP.
For now, the camera deployment has been paused, but the opposition wants Fico to replace Interior Minister Matúš Šutaj Eštok. The latter has acknowledged the risks, but Fico himself claims the cameras aren’t a threat to Slovakia.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
According to SME, a popular daily, Fico also contemplated that military satellites are now advanced enough to be able to read text on a piece of paper from orbit. That’s, of course, completely ridiculous – the “zoom and enhance” features seen in movies are fictional.
Also speaking to SME, security analyst Vladimír Bednár pointed out that Russia has been accessing speed and surveillance cameras in Ukraine to help plan attacks and assess their results.