Speed cameras shut down in Slovakia over remote access risk
Traffic cameras are meant to make roads safer, but they can create a very different problem when the technology itself is not secure. That is what has happened in Slovakia, where hundreds of speed cameras have been taken offline after authorities found serious security weaknesses.
Russian phone numbers on the devices
A total of 279 NERO R-ONE devices were deactivated after the National Security Authority of Slovakia discovered several vulnerabilities, reports Ziare. The problems involve both the software and questions about some of the equipment used in the cameras.
The cameras were bought as part of a traffic control modernization program supported by €30 million in European funding. It is not clear how much of that money was spent specifically on the radar systems.
One of the most serious problems involved remote access. Some of the devices reportedly contained a list of Russian phone numbers. Receiving a text message from one of those numbers could allow access to the device’s shell and network connection.
That could give someone the ability to send commands directly to the system instead of using its normal controls.
Produced in Russia?
The security problems did not stop there. Authorities also found weaknesses in Secure Boot. This is designed to prevent a device from starting with software that has been changed or is not authorized.
The cameras also had a web administration system that could reportedly be opened without a password if someone knew the device’s IP address. In some situations, this could allow a person to watch the cameras’ video feeds in real time.
The Slovak Interior Ministry has now stopped the use of the affected equipment. The findings will also be checked by an independent auditor.
The origin of the cameras has raised further questions. NERO R-ONE devices are believed to be rebranded versions of CORDON PRO.M cameras made in St. Petersburg, Russia.
There have also been claims that the equipment was bought through a company in Cyprus and included false certifications. However, those claims were not confirmed in the public warning issued by Slovakia’s security authority.
The authority officially lists three product categories. These include NERO R-ONE, linked to the Cypriot company SODASUS, along with two Cordon models associated with Russian manufacturer Simicon and Croatian company NEROline.
The case has now raised concerns over both cybersecurity and the checks carried out before public authorities purchase critical technology.