CVE-2026-42542
CVSS 7.5 HIGH: tDengine is an open source, time-series database optimized for Internet of Things devices. EPSS 0.6% (48th percentile).
Vulnerabilities & Exploits
Ridge Security disclosed CVE-2026-42542 in TDengine, a pre-authentication flaw in versions 3.4.0.0 through 3.4.1.5 that lets a remote attacker crash the database with one malformed packet on TCP 6030.
The bug is in TDengine’s custom binary RPC handling: before login, it trusts a packet length field, turns a bad value into an oversized copy, and the server process falls over. Ridge Security said the result is denial of service, and repeated packets can keep the database in a crash-restart loop.
For operators using TDengine to feed industrial telemetry, device monitoring, or OT dashboards, the immediate damage is not just an unavailable database. It is lost visibility and interrupted in-flight writes anywhere that port 6030 is reachable inside a flat internal or appliance network.
1 source · 22h ago
CVSS 7.5 HIGH: tDengine is an open source, time-series database optimized for Internet of Things devices. EPSS 0.6% (48th percentile).
Industrial Cyber
Ridge Security warns of high-severity TDengine vulnerability that can disrupt industrial telemetry and monitoring - Industrial Cyber
Ridge Security warns of a high-severity TDengine vulnerability that can disrupt industrial telemetry and monitoring.
originalPart of the PlainSec briefing for 2026-09-26
Every edition of this story: TDengine Flaw Can Drop Telemetry Visibility