A previously undisclosed flaw in Huawei enterprise router software was reportedly exploited to cause a nationwide telecom outage in Luxembourg, knocking out POST Luxembourg landline, 4G, 5G, and emergency communications for more than three hours. Investigators said specially crafted traffic passing through POST’s infrastructure forced Huawei routers into continuous reboot loops, and POST described the incident as a denial-of-service attack abusing a non-public, undocumented behavior rather than a conventional volumetric DDoS or any previously known vulnerability.
Authorities, Huawei, and European incident response partners reportedly coordinated on the case, but no public CVE or broad advisory has been issued and no criminal charges have been announced. Investigators found no evidence that POST Luxembourg was specifically targeted and no confirmed signs of wider exploitation, yet reporting indicates no patch was available at the time and it remains unclear whether the flaw has since been fully remediated or whether other telecom operators could still be exposed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In May 2026, media reports disclosed that the 2025 Luxembourg telecom crash was allegedly caused by a previously undisclosed Huawei router flaw. The reporting noted it remains unclear whether the issue was fully patched or whether other operators are still exposed.
Following the outage, Luxembourg authorities, Huawei, and European incident response partners reportedly coordinated on the incident. In the months after the event, no public CVE, broad warning, or criminal charges were issued, and no additional exploitation was confirmed.
Investigators determined that specially crafted traffic traversing POST Luxembourg’s infrastructure caused Huawei enterprise routers to enter continuous reboot loops. POST described the incident as a denial-of-service attack exploiting a non-public, undocumented behavior with no patch available at the time.
On July 23, 2025, POST Luxembourg suffered a nationwide outage that disrupted landline, 4G, 5G, and emergency communications for more than three hours.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcetherecord.media
Open sourcesdxcentral.com
Open sourcegouvernement.lu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.