Decoding the world of cybersecurity

Slovakia warns of risks in traffic cameras

Slovakia’s security authority has identified serious remote-access and software-security risks in NERO R-ONE traffic cameras, pushing a public procurement dispute into questions of infrastructure and product assurance.

Slovakia warns of risks in traffic cameras
Summary
  • Slovakia's National Security Authority identified multiple security risks after analysing a NERO R-ONE road-speed camera.
  • The public warning points to serious remote-management, software-security, and configuration concerns without attributing malicious intent.
  • The case combines embedded-device security with procurement assurance and the protection of connected public infrastructure.

Slovakia’s National Security Authority (NBÚ) has warned of multiple security risks in NERO R-ONE road-speed cameras after analysing equipment intended for the country’s traffic-monitoring infrastructure.

The authority said its technical examination identified weaknesses involving remote management, software security, and device configuration. Those findings move the case beyond a procurement controversy into a more concrete question of whether connected equipment deployed in public infrastructure can be trusted to behave only as documented.

Slovak authorities had already paused deployment while questions about the cameras were investigated. The wider programme has been reported as part of a roughly €30 million traffic-monitoring project supported with European funding.

NBÚ’s public summary does not itself attribute the devices to a hostile state actor or establish that any of the identified mechanisms were used maliciously. Specialist reporting on the fuller analysis has described contentious remote-access functionality, but the public warning is narrower: it confirms that the product contains security characteristics serious enough to justify intervention.

That distinction matters. Security reviews can establish unsafe architecture, undocumented access paths, weak software controls, or risky defaults without proving who designed them, why they exist, or whether they have ever been exploited. Procurement and national-security decisions still have to be made on the technical evidence that is available, not on assumptions about intent.

Traffic cameras are not isolated pieces of roadside hardware. Modern systems can communicate with management platforms, exchange data with government networks, and interact with databases containing vehicle or enforcement information. A weakness in the device can therefore create risk beyond the camera itself, particularly when systems are connected to wider monitoring and administrative infrastructure.

The episode illustrates the difficulty of assuring connected products acquired through complex supply chains. Procurement teams can check specifications, certifications, country of origin, and supplier documentation, yet those controls are weaker if the software and firmware actually running on a product behave differently from the documented design.

European policy is increasingly placing greater responsibility on manufacturers and suppliers for the security of connected products, while NIS2 has raised scrutiny of supply chain risk for operators in important and essential sectors. Those frameworks do not remove the need for buyers of specialist equipment to understand who built a device, how it is maintained, what remote-management functions exist, and which parties retain access after deployment.

The Slovak case also has a lifecycle dimension. Infrastructure equipment is often purchased for service lives measured in years rather than ordinary enterprise refresh cycles. An undocumented or poorly controlled management mechanism can remain embedded long after procurement officials, integrators, or original project teams have changed. Security assurance at purchase therefore has to be accompanied by the ability to inspect, update, and independently test products over time.

NBÚ’s warning gives Slovak authorities a concrete technical basis for deciding what happens next. Questions remain about how many NERO R-ONE devices were intended for deployment, whether identical weaknesses exist across the wider product estate, and what remediation or replacement would be required before any deployment resumed.

The incident is consequently also a test of public-sector supplier accountability: not simply whether a problematic product can be removed, but whether the procurement and assurance process can explain how equipment with serious security weaknesses reached a national infrastructure programme in the first place.

×