Ten months later, nobody knows why Huawei routers took down Luxembourg's phone network- 243
July 7, 2026
For more than three hours on July 23, 2025, landline, 4G, and 5G service across Luxembourg went dark simultaneously, leaving potentially hundreds of thousands of residents unable to reach emergency services — the result of specially crafted network traffic that sent Huawei enterprise routers into a continuous restart loop. Ten months on, the vulnerability responsible has never received a CVE identifier, no public warning has reached the other network operators running the same equipment worldwide, and Huawei has declined to explain why.
The technical story, as reconstructed by POST Luxembourg's own head of communications Paul Rausch, describes a denial-of-service attack exploiting what he called "a non-public, non-documented behaviour, for which no patch was available at the time" — a description carefully distinct from any previously known or documented vulnerability. Huawei reportedly told POST it had never encountered the specific attack pattern among any of its other customers and had no ready-made fix available when the incident occurred. Investigators from Luxembourg's police and cybersecurity authorities later determined that corrupted data, potentially crafted to prepare an attack against some unrelated random server elsewhere on the internet, had simply been relayed through POST's infrastructure in its normal role as an internet service provider — and instead of forwarding that traffic onward as intended, the Huawei routers hit an undocumented failure state that caused them to repeatedly crash and reboot.

Luxembourg's government initially described the incident as "an exceptionally advanced and sophisticated cyberattack," language POST later clarified referred specifically to the technical expertise required to trigger the flaw, not to any deliberate targeting of Luxembourg itself — investigators ultimately found no evidence the attack was specifically directed at POST as a chosen target, and no criminal charges have been filed.
That distinction — a nationwide telecoms outage apparently triggered by traffic that wasn't even aimed at the network that collapsed — is what makes this incident more unsettling than a conventional targeted attack would be. If malformed traffic merely passing through a network device can crash a national telecommunications infrastructure without any specific intent behind it, the same undocumented failure condition could plausibly be triggered again, accidentally or otherwise, anywhere else the same Huawei hardware and software version is deployed. Huawei's VRP network operating system has previously disclosed comparable denial-of-service flaws, tracked as CVE-2021-22359 and CVE-2022-29798, both involving specially crafted protocol traffic — but POST confirmed neither of those known vulnerabilities was involved in the Luxembourg incident, meaning this is a distinct, still-undocumented flaw with no public identifier attached to it at all.

The disclosure gap sitting at the center of this story reflects a broader pattern in how Huawei handles enterprise vulnerability reporting compared to its consumer product line, where CVE filings remain routine. For enterprise networking software, the company has increasingly relied on a restricted customer portal for security advisories rather than public CVE disclosure, with many of the vulnerabilities that do become public knowledge originating from independent security researchers rather than from Huawei itself. One such restricted advisory, describing an unrelated denial-of-service flaw involving packet parsing, was published last month without a CVE identifier either — though there is no evidence connecting it to the Luxembourg incident specifically. Luxembourg's cybersecurity authorities did alert partner incident response teams across Europe through established government channels following the outage, and held follow-up technical meetings with Huawei to understand what had happened — but responsibility for actually filing a public CVE rests entirely with the vendor under standard industry disclosure procedures, and Huawei has simply chosen not to exercise it. Ten months after a Huawei router crash cut off a European country's emergency communications for three hours, the company that makes the equipment still hasn't told the rest of the world's network operators what went wrong, or whether their own infrastructure carries the same undocumented weakness.