Huawei
– Giacomo Lee/SDxCentral

An outage that took down Luxembourg's entire telecom network was pinpointed to a previously undisclosed vulnerability in Huawei enterprise router software.

According to The Record, Paul Rausch, head of communications at state-owned operator Post Luxembourg, confirmed a denial-of-service (DoS) attack targeted a network device by exploiting a zero-day flaw. Huawei told the operator it had never encountered the attack previously and as such could not offer remediation.

The report added the flaw remains unexplained with no associations to any previously documented vulnerabilities, and is yet to be publicly acknowledged by the Chinese giant.

The incident in question occurred on July 23, 2025, when specially crafted network traffic forced Huawei enterprise routers into a continuous restart loop, disabling critical components of Post Luxembourg's infrastructure and leaving landline, 4G, 5G, and emergency communication services offline for more than three hours.

While Luxembourg’s government initially characterized the incident as a cybersecurity attack, investigators found no evidence that Post Luxembourg was deliberately targeted.

The report noted that while Huawei regularly files CVEs for consumer products, public disclosures of vulnerabilities affecting its enterprise networking software have become increasingly uncommon and are distributed through a restricted customer portal rather than publicly.

Huawei did not respond to questions from The Record about why a public CVE hadn't been issued for the vulnerability behind Post Luxembourg’s nationwide outage.