Vulnerabilities · 3h ago

TDengine Packet Crash Threatens OT Visibility

Ridge Security disclosed CVE-2026-42542 in TDengine, a time-series database used across industrial, IoT, energy, and vehicle environments, and says a single crafted packet can crash affected servers. The flaw affects TDengine 3.4.0.0 through 3.4.1.5; TDengine has shipped 3.4.1.6 as the fixed release.

The bug sits in code that runs before the server has checked who sent the packet, so an unauthenticated attacker can knock the process over without logging in. In OT and IoT deployments, that is less a data-theft problem than an interruption problem: telemetry, historian, monitoring, and other control-adjacent services can go blind when the database drops.

The harder part is deployment reach. TDengine says it is widely used, and the same database may be embedded inside appliances, so some vulnerable instances can stay exposed long after the vendor has a fix. For teams that depend on it in plant, fleet, or infrastructure workflows, the exposure lasts wherever the software is still running and still reachable.

CVE-2026-42542

NVD KEV

CVSS 7.5 HIGH: tDengine is an open source, time-series database optimized for Internet of Things devices. EPSS 0.6% (48th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-28

Editions

Related stories