Slovakia’s National Security Bureau (NBÚ) issued a cybersecurity alert after analyzing NERO R-ONE road-speed cameras used in the country’s traffic monitoring system and finding what it described as a significant cyber threat. The agency said the devices, reportedly rebranded Russian CORDON PRO.M units made by Semicon/Simicon in St. Petersburg, contained a backdoor capable of executing malicious code delivered by SMS from hardcoded Russian phone numbers. NBÚ also reported discrepancies between the products’ declared and actual hardware and software origin, undocumented communication interfaces, preconfigured remote access and management functions, mismatches in measurement-processing software, disabled SecureBoot, vulnerabilities in the web management portal, and unauthenticated exposure of live video streams.
The warning covers NERO R-ONE by SODASUS as well as Cordon-series products linked to Simicon and NEROline, and NBÚ urged essential service operators and other organizations to identify any such devices in their infrastructure and report them. The cameras were procured through a no-bid contract from a Cyprus shell company under a €30 million EU-funded project, with 279 units installed on Slovak roads. Following the findings, Slovakia’s Interior Ministry paused further deployment and said it would seek an independent audit to verify the report, while the observed risks were aligned with MITRE ATT&CK techniques T1195.003 for hardware supply-chain compromise and T1133 for external remote services.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-14, Slovakia's National Security Bureau (NBÚ) published an official cybersecurity alert, issued at the request of the Interior Ministry, covering NERO R-ONE and certain Cordon-series road radar products. NBÚ classified the matter as a significant cyber threat and told operators to identify affected products in their infrastructure and report any presence to the agency.
After NBÚ's findings, the Slovak Interior Ministry deactivated NERO R-ONE traffic cameras that had already been installed and configured. This went beyond merely pausing deployment while an independent review of NBÚ's conclusions was expected.
Following NBÚ's report, Slovakia's Interior Ministry paused deployment of the traffic cameras. The ministry also said it would commission an independent audit or additional assessment to verify NBÚ's findings.
NBÚ's technical analysis of a borrowed NERO R-ONE sample found multiple serious issues, including a backdoor that could execute malicious code via SMS from hardcoded Russian phone numbers, disabled SecureBoot, vulnerabilities in the web management portal, exposed live video streams, undocumented or inaccessible remote-management mechanisms, and mismatches between declared and actual hardware, software, and measurement-processing components. NBÚ also assessed the NERO R-ONE cameras as rebranded Russian CORDON PRO.M units made by Semicon in St. Petersburg.
Slovak media reported concerns about the procurement of NERO R-ONE traffic cameras, including that they were bought through a no-bid direct contract involving a Cyprus shell company with fake certifications. These reports prompted Slovakia's national security authority NBÚ to begin investigating the devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcetomshardware.com
Open sourcecyberveille.ch
Open sourcenews.risky.biz
Open sourcenbu.gov.sk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.