Slovakia's National Security Authority (NBÚ) has issued a warning regarding significant cybersecurity risks associated with several types of road speed cameras, identifying them as potential threats to public networks and sensitive vehicle data. The alert, prompted by a request from the Interior Ministry, focuses on connected devices that collect vehicle information, communicate with other systems, and may feature remote access functionalities not fully controllable by the operator.
The NBÚ's analysis specifically examined a sample of the NERO R-ONE camera system and named three product lines in its warning: NERO R-ONE devices from Cyprus-based SODASUS, Cordon-series speed cameras manufactured by Russia's Simicon, and Cordon-series products distributed by Croatia's NEROline. The authority emphasized that the issues extend beyond simple configuration problems.
Key findings from the security analysis include discrepancies between documented and actual communication settings, ambiguity regarding the true origin of the hardware and software, software versions that did not match declared specifications, and weak security protections. A particular concern highlighted was the presence of pre-configured remote access and product management mechanisms that were not entirely under the customer's control.
Such uncontrolled remote access creates a blind spot in systems that may be integrated into public-sector networks or interact with other operational services. Speed cameras are sophisticated devices that photograph vehicles, record timestamps, process license plate data, store evidence, and transmit information to backend systems used by authorities. They can also connect to mobile networks, roadside equipment, police systems, municipal platforms, or third-party maintenance services.
The NBÚ warned that if these cameras are compromised, attackers could gain unauthorized access to data, alter or delete records, manipulate violation measurements or reporting, or even disable the cameras. Furthermore, if network segmentation is inadequate, a compromised camera could serve as an entry point to other critical systems. The warning aims to alert operators of essential services and other organizations to these serious cybersecurity risks, which could potentially be exploited to disrupt networks, systems, or services.
In response to the investigation, the Slovak Interior Ministry reportedly removed the equipment from its pilot deployment. The ministry also requested that the supplier remove the units and replace them with equipment that complies with Slovak and EU legal, technical, and security requirements.
The NBÚ's warning does not assert that every device is actively spying or contains a proven backdoor. Instead, it highlights identified security risks, limitations in operator control, uncertainties regarding hardware and software provenance, and remote management mechanisms that could not be fully accounted for.
The authority stressed the importance of thorough security checks for connected public devices, which should not rely solely on brand names, country of origin on invoices, or vendor claims. Operators need to have clear knowledge of the software and firmware running on devices, how remote access functions, and who controls it. Recommendations include independent security testing, secure update processes, and robust network segmentation. This advice extends beyond Slovakia, applying to a wide range of smart infrastructure components such as license plate readers, parking sensors, environmental monitors, and traffic lights, which are often managed by public agencies, contractors, and manufacturers.






