Traffic cameras with backdoors: SMS grants remote access
Security researchers found a Slovakian traffic radar system using undocumented Russian firmware, allowing remote control via SMS and exposing an unencrypted video stream.
Slovak security authorities have flagged traffic speed cameras as a severe cyber threat after discovering that a single SMS could remotely activate backdoors on devices manufactured by the Russian firm Simicon.
The Slovak National Security Agency (NBÚ) analyzed pilot units of the NERO R-ONE and Cordon models, finding undocumented mobile mechanisms including twelve hardcoded Russian phone numbers. Sending an SMS to one of these numbers grants full remote shell access and network control, effectively turning the device into a remote-controlled vehicle.
Further vulnerabilities include an unsecured RTSP video stream accessible without a password and disabled Secure Boot, which prevents firmware integrity checks. While the manufacturer listed on the interface is Cypriot firm Sodasus, hardware analysis confirmed the underlying platform belongs to Simicon based in St. Petersburg.
The Slovak Interior Ministry has removed these units from pilot deployment and launched a criminal investigation into their procurement. Authorities warn other organizations to check for similar devices in their infrastructure, noting that while no active exploitation has been confirmed, the remote access mechanism poses an immediate risk.