Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

TDengine vulnerability lets one unauthenticated packet crash industrial databases

Ridge Security says a flaw fixed in TDengine 3.4.1.6 lets anyone who can reach port 6030 knock the database offline with a single crafted packet.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1CVE-2026-42542 lets an unauthenticated attacker crash TDengine versions 3.4.0.0 through 3.4.1.5 with one crafted packet to port 6030.
  • 2The TDengine project rates it high severity at CVSS 7.5 and fixed it in version 3.4.1.6.
  • 3Ridge Security says it has seen no exploitation, but downed databases mean lost telemetry and silent alarms for operators.

The news

A TDengine vulnerability lets an attacker with no password crash the time-series database with one malformed network packet, Ridge Security said in research published September 23, 2026. Ridge said TDengine is designed for industrial telemetry, energy and connected-vehicle monitoring.

The flaw, tracked as CVE-2026-42542, affects TDengine versions 3.4.0.0 through 3.4.1.5 and is fixed in version 3.4.1.6, according to a security advisory in the TDengine GitHub repository. The advisory, published June 4, 2026, rates the issue high severity with a CVSS score of 7.5 and credits it to a reporter identified as shook-zhou. Ridge credits the research to Yan Zhou.

The bug sits in TDengine's transport layer, in code that processes remote procedure call (RPC) messages before any login. According to the advisory, a message that declares a length shorter than the header data the server expects causes an integer underflow: a subtraction that should produce a small number wraps around to an enormous one. The server then tries to copy that much memory, and the database process, called taosd, crashes.

Ridge said the attack works against TCP port 6030, TDengine's default, and needs no credentials, session or user interaction. The advisory's scoring vector reflects that: the attack is network-based, low in complexity and requires no privileges. The same scoring lists no impact on confidentiality or integrity, only on availability, meaning the flaw is a denial-of-service risk rather than a route to steal or alter data.

Ridge Security said it has no telemetry showing exploitation in the wild and is not aware of public exploit code. It said the issue was reported to TDengine's maintainers through coordinated disclosure and gave the project credit for its handling. Ridge, which sells penetration testing and adversary emulation products, did not say how many vulnerable TDengine servers are reachable from the internet.

The numbers

CVE
CVE-2026-42542
CVSS score (TDengine advisory)
7.5, high
Affected versions
3.4.0.0 through 3.4.1.5
Fixed version
3.4.1.6
Default port exposed to the attack
TCP 6030
Packets needed to crash the server
1

Why CEOs should care

For operations and plant leaders, the risk is lost visibility. Ridge noted that when the database goes down, data being written at that moment is lost, and a monitoring system that is down cannot raise alerts. It said time-series databases sit behind factory SCADA systems, EV charging networks and building automation. Where TDengine plays that role, a crash could leave operators without live data until the service restarts. Ask your OT team whether any system you run, or any vendor product you bought, uses TDengine 3.4.x, and whether it has been updated to 3.4.1.6.

For CISOs, the fix is clear but the inventory is the hard part. Time-series databases are often bundled inside vendor platforms rather than installed by IT, so they may not appear in asset lists. Ridge recommends upgrading, restricting port 6030 to authorized hosts with firewall rules or network access control lists if patching must wait, searching for embedded TDengine deployments, and watching for repeated taosd crashes or restart loops. Unexplained gaps in time-series data are another sign worth investigating.

For boards and risk committees, this is a useful test of how fast OT patches move. The fix has been available since at least June 4, according to the advisory, and full technical details are now public. A good question for management: how long does it take us to deploy a vendor fix to a production industrial system, and who signs off on the downtime?

The bigger picture

Industrial companies have spent years connecting plant equipment to data platforms for analytics and predictive maintenance. That brings IT-style software, and IT-style bugs, into environments where uptime matters most. A flaw that needs no password and one packet shows why OT networks should not let data services such as databases accept connections from anywhere. Once researchers publish the mechanics of a bug, as Ridge has here, writing an exploit tends to get easier, so the period between public details and patching is when unexposed, updated systems matter most.

What’s next

Watch for any sign of exploitation, for inclusion in government exploited-vulnerability lists, and for advisories from industrial software vendors that embed TDengine and must ship their own updates. Operators that cannot upgrade soon should confirm that port 6030 is reachable only by the hosts that need it.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

TDengineRidge SecurityCVE-2026-42542OT security

Earlier coverage of GitHub

All GitHub coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.