CVE-2026-42542
CVSS 7.5 HIGH: tDengine is an open source, time-series database optimized for Internet of Things devices. EPSS 0.6% (48th percentile).
Vulnerabilities · 21h ago
Ridge Security disclosed CVE-2026-42542 in TDengine, a pre-authentication flaw in versions 3.4.0.0 through 3.4.1.5 that lets a remote attacker crash the database with one malformed packet on TCP 6030.
The bug is in TDengine’s custom binary RPC handling: before login, it trusts a packet length field, turns a bad value into an oversized copy, and the server process falls over. Ridge Security said the result is denial of service, and repeated packets can keep the database in a crash-restart loop.
For operators using TDengine to feed industrial telemetry, device monitoring, or OT dashboards, the immediate damage is not just an unavailable database. It is lost visibility and interrupted in-flight writes anywhere that port 6030 is reachable inside a flat internal or appliance network.
CVSS 7.5 HIGH: tDengine is an open source, time-series database optimized for Internet of Things devices. EPSS 0.6% (48th percentile).
1 source covering this story
Ridge Security warns of a high-severity TDengine vulnerability that can disrupt industrial telemetry and monitoring.
Part of the PlainSec briefing for 2026-09-26