Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a significant cyber threat. The alert is not about someone deleting a speeding ticket. It is about connected devices that collect vehicle data, communicate with other systems, and may contain remote-access functions that the operator cannot fully control.
The Slovak authority examined a sample of the NERO R-ONE camera system at the request of the Interior Ministry. It named three product lines in its warning: NERO R-ONE devices sold by Cyprus-based SODASUS, Cordon-series speed cameras made by Russia’s Simicon, and Cordon-series products sold by Croatia’s NEROline.
“The National Security Authority warns of a significant cyber threat associated with the use of several types of road speed cameras.” reads the alert. “A security analysis has identified several risks and recommends that affected entities identify the products in question in their infrastructure.”
The problems went beyond a simple configuration issue. NBÚ found differences between the documented and actual communication settings, uncertainty about where the hardware and software came from, software that did not match the declared version, and weak security protections.
“The security analysis identified several risks, including the true origin of the camera hardware and software, inconsistency between the documented and detected configuration of the product’s communication interfaces, and pre-configured remote access and product management mechanisms.” the agency wrote on LinkedIn.
That last point deserves attention. A road camera should be managed by the organisation that owns it, under controls that it can inspect, configure and audit. If a device includes pre-set remote-access or management mechanisms outside the customer’s full control, it creates a blind spot in a system that may sit on a public-sector network or communicate with other operational services.
Speed cameras do much more than take pictures and measure speed. They photograph vehicles, record timestamps, process licence-plate data, store evidence and send information to backend systems used by authorities. Depending on the setup, they may also connect to mobile networks, roadside equipment, police systems, municipal platforms or third-party maintenance services.
If attackers compromise a camera, they could access data, change or delete records, manipulate how it measures or reports violations, or shut it down. If the network lacks proper segmentation, they could also use the camera as a foothold to reach other systems. The camera may not be the real target. It could simply be the unlocked door.
The warning aims to alert essential-service operators and other organisations that these road cameras could pose a serious cybersecurity risk. In the wrong circumstances, attackers could use them to disrupt networks, systems or services.
The Slovak Interior Ministry reportedly took the equipment out of its pilot deployment while the matter was investigated. Public reporting also says the ministry asked the supplier to remove the units and replace them with equipment meeting Slovak and EU legal, technical and security requirements.
The Russian connection adds an obvious geopolitical dimension, but it should not become a substitute for technical analysis. NBÚ did not say that every device was actively spying on users or that the equipment contained a proven backdoor. Its warning is about identified security risks, limited operator control, uncertainty over hardware and software provenance, and remote-management mechanisms that could not be fully accounted for.
That is enough reason to take action. Security checks for connected public devices cannot rely only on the brand, the country listed on the invoice or the vendor’s claims. Operators should know exactly what software and firmware the device runs, how remote access works and who controls it. They should also use independent security testing, secure updates and network segmentation.
The same lesson applies beyond Slovakia. Smart cameras, licence-plate readers, parking sensors, environmental monitors, traffic lights and roadside communication systems are becoming part of public infrastructure. They are often cheap, easy to overlook and managed by public agencies, contractors and manufacturers. That makes them just as important to secure as other critical systems.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Speed Cameras)