3 min read

The Undisclosed Flaw: How a Huawei Zero-Day Took Down Luxembourg's Entire Telecoms Network- 183

The Undisclosed Flaw: How a Huawei Zero-Day Took Down Luxembourg's Entire Telecoms Network- 183

June 14, 2023

A country's entire telecommunications network — landline, 4G, 5G, emergency services — went dark for more than three hours because of a vulnerability that has never been publicly disclosed, for which no CVE has ever been filed, and about which no warning has been issued to any other operator running the same equipment. The flaw, in Huawei enterprise routers, is still undescribed in any public database ten months after the incident. This is not a story about what happened in Luxembourg on July 23, 2025. It is a story about what happens when the vendors controlling critical telecommunications infrastructure treat vulnerability disclosure as an internal matter.

On July 23, 2025, POST Luxembourg's landline, 4G, and 5G mobile networks went down simultaneously. Hundreds of thousands of residents were unable to reach emergency services. When connectivity was restored more than three hours later, the country's emergency call center received hundreds of additional calls — the backlog of people who had been trying to get through. The Luxembourg government described the incident at the time as "an exceptionally advanced and sophisticated cyberattack." Ten months later, the vulnerability that caused it has never been publicly disclosed. No CVE identifier has been filed. No public warning has been issued to other operators running the same equipment.

The outage was triggered by specially crafted network traffic that sent Huawei enterprise routers into a continuous restart loop, crashing critical parts of POST's infrastructure. POST's head of communications Paul Rausch confirmed to Recorded Future News that the incident exploited "a non-public, non-documented behaviour, for which no patch was available at the time" and was "not related to the exploitation of any known or previously documented vulnerabilities." Huawei told POST it had never encountered the attack among any of its customers and had no ready-made solution. Multiple sources briefed on the incident described it as a zero-day attack. POST separately confirmed it was not a volumetric DDoS attack of the kind typically associated with hacktivists — it was precision targeting of an undocumented router failure condition.

Luxembourg's investigators ultimately concluded there was no evidence that the attack was specifically directed at POST as a chosen target. The public prosecutor's office described how "corrupted data, which may be used to prepare an attack on a random server responding to it, had been relayed through POST Luxembourg acting in its role as internet service provider and caused their systems to stop and reboot instead of simply relaying the data." The suggestion, extraordinary in its implications, is that the outage may have been triggered by maliciously crafted network traffic simply passing through POST's infrastructure — traffic directed elsewhere, incidentally causing a nationwide telecoms failure because Huawei routers hit an undocumented failure condition when they encountered it. If accurate, this transforms the incident from a targeted attack into a demonstration of fragility: a major European country's entire communications network collapsing not because it was the target but because its core infrastructure could not safely handle malicious transit traffic.

The disclosure gap is where the incident moves beyond a single operator's problem. Huawei routinely files CVEs for consumer products, but public disclosures involving vulnerabilities in its enterprise networking software have become rare in recent years. The company publishes enterprise security advisories through a restricted customer portal rather than broad public advisories — a practice that limits the defensive value of whatever remediation it does communicate. Under standard disclosure procedures, the decision to file a CVE rests with the vendor. Huawei did not comment about why no CVE had been issued for a vulnerability that caused a nationwide telecoms outage. Luxembourg authorities alerted partner incident response teams across Europe through government channels. The broader community of operators running the same Huawei equipment, unconnected to those government channels, received no warning at all. Ten months after the incident, it remains unclear whether the vulnerability was ever fully patched, how many other operators may be exposed, or whether similar Huawei systems remain vulnerable today.

The Luxembourg case illuminates a structural problem in the security of critical communications infrastructure that extends beyond any single vendor or any single country. Telecoms networks built on enterprise routing equipment from vendors who treat vulnerability disclosure as an internal customer-portal matter, rather than a public security obligation, are operating with a hidden attack surface that defenders cannot see. The outage lasted three hours. A deliberately targeted operation against the same vulnerability in a different context — one designed to disrupt rather than accidentally triggered by transit traffic — would have no reason to be briefer.