Forgot your password?
typodupeerror
Government Privacy Security

Slovakia Finds Russian Backdoor In Traffic Speed Cameras (tomshardware.com) 44

Slovakia acquired speed cameras to modernize its traffic control-- but there was a surprise. Tom's Hardware cites this story from the Risky Bulletin Newsletter: Unfortunately, the country's national security service, the NBU, has discovered that the cameras have multiple security issues. Firstly, they have SMS-activated Russian backdoors. Secondly, live camera feeds can be accessed by anyone with the device IP, no password necessary...

[The cameras] are thought to be rebranded Russian CORDON PRO.M traffic cameras, produced by a St. Petersburg-based firm called Semicon... reportedly bought via a Cyprus-based shell company with fake certifications. Reports also suggest that pressure from the opposition political party in Slovakia led to the NBU investigations... Probably most seriously, in terms of national security, these cameras contain a hardcoded list of Russian phone numbers, which can be used to open a backdoor. An SMS from one of these numbers can open shell and network access... [T]he SecureBoot feature is ineffective, and the web management portal can be accessed, exposing live streams, by anyone with the camera IP.

Cameras that have been installed and set up have since been deactivated by the Slovak Ministry of the Interior. Meanwhile, for due diligence, an independent auditor will be called in to confirm the NBU's findings. It is thought that Croatia, and some other countries in Eastern Europe, may have undiscovered issues with traffic control cameras of similar origin.

This discussion has been archived. No new comments can be posted.

Slovakia Finds Russian Backdoor In Traffic Speed Cameras

Comments Filter:
  • by XXongo ( 3986865 ) on Sunday August 23, 2026 @01:44PM (#66303402) Homepage
    Hmm. Probably originally implemented to enable Kremlin surveillance of Russians (in Russia), but there was no reason to remove the surveillance back door for the export version/
    • Hmm. Probably originally implemented to enable Kremlin surveillance of Russians (in Russia), but there was no reason to remove the surveillance back door for the export version/

      The Kremlin would just get the installers to give them the direct access. No need with getting special complex software features written. Also, historically their crypto stuff has not been bad and has been paranoid so this is unlikely to be official. This is either done by private people associated with the company or, more likely, done by Russia with the speculative hope that they get installed somewhere interesting abroad. Likely there are hundreds of these cameras in countries all over the world and if t

      • >The Kremlin would just get the installers to give them the direct access

        What, you mean something like...

        > these cameras contain a hardcoded list of Russian phone numbers, which can be used to open a backdoor
        • No, I mean like "the UI is at IP a.b.c.d and the password is 'password', now integrate it to the monitoring dashboard". Following which the whole history of each camera would be available on demand wherever the management system is.

          Which is the opposite of a weird backdoor involving sending text messages from a specific dedicated list of phones.

    • by 93 Escort Wagon ( 326346 ) on Sunday August 23, 2026 @02:40PM (#66303524)

      Nonsense. This backdoor was obviously put into place so Russian tanks could disable the cameras and speed through the cities, traversing Slovakia quickly on their way to the west. But, now that it's been discovered, those tanks will need to obey the traffic laws - foiling any invasion!

    • Hmm. Probably originally implemented to enable Kremlin surveillance of Russians (in Russia), but there was no reason to remove the surveillance back door for the export version/

      That I very much doubt, these were probably prepared for export. I can think of a few questions here:
      - some Slovakian political parties are pro Russian, what was their role in this debacle?
      - what is the background for the Cypriot "shell company" involved?
      - what numbers are they using for the SMS messages? Specifically, the country code.
      - the SMS-activated Russian backdoors depend on which network? G2, G3, G4 or even G5?

    • Preved! Bear surprise now camera surprise!
  • Would a properly installed firewall stop someone from accessing this via the IP?

    Seems to me that is what firewalls are supposed to do - stop random people from accessing IP addresses on your network.

    • If your last line of defense against state-sponsored spying is IP-based filtering, you are pwned. Especially with an SMS-based backdoor.
    • Re:Firewall? (Score:4, Informative)

      by drinkypoo ( 153816 ) <drink@hyperlogos.org> on Sunday August 23, 2026 @02:06PM (#66303454) Homepage Journal

      Would a properly installed firewall stop someone from accessing this via the IP?

      The short answer is yes, but the longer answer is it's complicated.

      Devices with back doors may also dial out from your network. It's common for devices to phone home to check for updates and such so such activity is not necessarily even seen as suspicious, though of course in an enterprise context you should be disabling automatic updates and/or reconfiguring them to use internal servers.

      Devices which might be malicious should be segregated onto their own physically isolated networks connected only through firewalls with policies for both ingress and egress so that you can control both types of threat. But it's better still when your software and firmware is OSS, and you build your own images and deploy them to the hardware yourself to have the best chance to avoid the possibility in the first place. Even this doesn't completely preclude such attacks, but it does offer some protection (mostly in proportion to the level at which you're auditing the source files, and the percentage of OSS.)

      TL;DR: It's smartest to segregate and whitelist traffic in both directions for sketchy devices.

      • You can buy NGFW that will do packet inspection on everything and setup rules for every packet. If you are serious about security, you aren't letting anything out that isn't already allowed to go out.

        Now, the device will take at least a week or so to really see all the traffic but once you've identified everything that's on your network, anomalies are that much easier to see and shutdown.

        We have the tools. We just need to get management to understand the importance of them and why purposely poking holes for

      • my mod troll is big mad I got a good comment score so he downmodded me three times to prove how broken Slashdot moderation is by design

    • by Bert64 ( 520050 )

      For an SMS based backdoor, no. It seems these devices are designed to use cellular connections (which makes sense since traffic cameras will be installed in remote locations).

      And then most firewalls focus on inbound connections, but often do nothing to prevent a compromised device from making outbound connections. SMS could easily be used to initiate an outbound connection.

    • by gweihir ( 88907 )

      That is the wrong approach. To firewall these, you need to know the type and nature of the backdoors in there. But once you know that, you reject the product.

      Also, a firewall does nothing for SMS unless you do SS7 firewalling, which is very, very hard to do and requires expensive equipment.

  • by 0123456 ( 636235 ) on Sunday August 23, 2026 @01:48PM (#66303420)

    Why is it that "modernize" always seems to mean "do more to turn humans into bug-men"?

  • Repeat after me... (Score:3, Interesting)

    by MpVpRb ( 1423381 ) on Sunday August 23, 2026 @02:13PM (#66303464)

    Speed Cameras Suck!
    Mightily!
    They should be opposed anywhere they are used, with or without Russian backdoors

    • by Bruce66423 ( 1678196 ) on Sunday August 23, 2026 @02:28PM (#66303488)

      Given the vast numbers killed on the roads in the West, especially in the USA, and the clear evidence that slower cars do less damage in accidents, there is a good case for installing them aggressively. Near where I live a freeway comes to a sudden pedestrian crossing as it enters the suburbs of my city - and enforcing slower speeds in the approach to that crossing is clearly worthwhile. By contrast there is sometimes a camera on the way OUT of the city, beyond the crossing - where there is no further stops - and that makes no sense.

      • Except the camera didn't enforce anything. It reacted after the fact. Also, are you sending the ticket to the driver or the person the car is registered under? I think California does the later and it's a cheap ticket that you can ignore because it wasn't actually issued by an officer.

        All the camera is doing is tracking all the cars. That's why they need the one for you leaving town as well. It's not about public safety but overreach by government to control our lives.

      • Given the vast numbers killed on the roads in the West, especially in the USA, and the clear evidence that slower cars do less damage in accidents, there is a good case for installing them aggressively. Near where I live a freeway comes to a sudden pedestrian crossing as it enters the suburbs of my city - and enforcing slower speeds in the approach to that crossing is clearly worthwhile. By contrast there is sometimes a camera on the way OUT of the city, beyond the crossing - where there is no further stops - and that makes no sense.

        A) turning everything into a police action,
        and thus needing to deploy massive surveillance infrastructure across the planet to police everything,
        and then finally outsourcing policing to businesses,
        to protect the perpetual revenue stream for contractors.

        B) build a pedestrian bridge/tunnel at a dangerous intersection. Protect human beings.

        Guess which one government officials love most?

        • A feature of my area is that the pedestrian crossing across the freeway I refer to above is between two areas of social housing (projects). About 3 miles away there is a similar, though somewhat less busy, freeway located near a school to which the relatively wealthy parents send their kids. THAT'S got a bridge...

  • I wonder who makes their cameras and what backdoors they may have; it’s an intelligence agencies wet dream: a potential adversary pays to install and maintain hour intelligence gathering tools.
    • Re:Flock (Score:4, Interesting)

      by ArchieBunker ( 132337 ) on Sunday August 23, 2026 @03:09PM (#66303570)

      Here is a teardown https://www.cehrp.org/dissecti... [cehrp.org]

      • by AmiMoJo ( 196126 )

        Thanks, but unfortunately some of the information there is wrong or misleading. For example, what they call a "GPS module" is actually just an active antenna, basically a GNSS antenna with a built in LNA.

        The bigger issue is that there are a lot of modules that we don't know the contents of. For example, the NimbeLink Skywire LTE modem contains a Sierra Wireless modem, which itself is made from parts from another company. Maybe Chinese, maybe not. Incidentally, the GNSS receiver is likely in there too. Combi

  • Some of the models used in the UK can be hacked through a local wireless engineering interference. You get a root shell and can, for example, erase your driving offences and evidence if you know you've been flashed. Since those older cameras upload data at certain specific time intervals, if you act quickly enough, you can nuke the database and make it look like nothing has ever happened.

  • Slovakia's Prime Minister Robert Fico made a lot of noise awhile back sucking up to Putin. Did he expect some sort of respect to flow back the other way?

  • by gweihir ( 88907 ) on Monday August 24, 2026 @05:37AM (#66304172)

    Now if all these idiots claiming Chinese backdoors would either shut up or deliver evidence.

  • When I want a speedy Russian backdoor, I find your mom.

    Traditions matter, guys.
  • Supply chain needs block chain.

  • is the srouce of flock's hardware. And Axion.

  • How hard would it be to replace the software on these devices?

To thine own self be true. (If not that, at least make some money.)

Working...