The news
A TDengine vulnerability lets an attacker with no password crash the time-series database with one malformed network packet, Ridge Security said in research published September 23, 2026. Ridge said TDengine is designed for industrial telemetry, energy and connected-vehicle monitoring.
The flaw, tracked as CVE-2026-42542, affects TDengine versions 3.4.0.0 through 3.4.1.5 and is fixed in version 3.4.1.6, according to a security advisory in the TDengine GitHub repository. The advisory, published June 4, 2026, rates the issue high severity with a CVSS score of 7.5 and credits it to a reporter identified as shook-zhou. Ridge credits the research to Yan Zhou.
The bug sits in TDengine's transport layer, in code that processes remote procedure call (RPC) messages before any login. According to the advisory, a message that declares a length shorter than the header data the server expects causes an integer underflow: a subtraction that should produce a small number wraps around to an enormous one. The server then tries to copy that much memory, and the database process, called taosd, crashes.
Ridge said the attack works against TCP port 6030, TDengine's default, and needs no credentials, session or user interaction. The advisory's scoring vector reflects that: the attack is network-based, low in complexity and requires no privileges. The same scoring lists no impact on confidentiality or integrity, only on availability, meaning the flaw is a denial-of-service risk rather than a route to steal or alter data.
Ridge Security said it has no telemetry showing exploitation in the wild and is not aware of public exploit code. It said the issue was reported to TDengine's maintainers through coordinated disclosure and gave the project credit for its handling. Ridge, which sells penetration testing and adversary emulation products, did not say how many vulnerable TDengine servers are reachable from the internet.
The numbers
- CVE
- CVE-2026-42542
- CVSS score (TDengine advisory)
- 7.5, high
- Affected versions
- 3.4.0.0 through 3.4.1.5
- Fixed version
- 3.4.1.6
- Default port exposed to the attack
- TCP 6030
- Packets needed to crash the server
- 1
Why CEOs should care
For operations and plant leaders, the risk is lost visibility. Ridge noted that when the database goes down, data being written at that moment is lost, and a monitoring system that is down cannot raise alerts. It said time-series databases sit behind factory SCADA systems, EV charging networks and building automation. Where TDengine plays that role, a crash could leave operators without live data until the service restarts. Ask your OT team whether any system you run, or any vendor product you bought, uses TDengine 3.4.x, and whether it has been updated to 3.4.1.6.
For CISOs, the fix is clear but the inventory is the hard part. Time-series databases are often bundled inside vendor platforms rather than installed by IT, so they may not appear in asset lists. Ridge recommends upgrading, restricting port 6030 to authorized hosts with firewall rules or network access control lists if patching must wait, searching for embedded TDengine deployments, and watching for repeated taosd crashes or restart loops. Unexplained gaps in time-series data are another sign worth investigating.
For boards and risk committees, this is a useful test of how fast OT patches move. The fix has been available since at least June 4, according to the advisory, and full technical details are now public. A good question for management: how long does it take us to deploy a vendor fix to a production industrial system, and who signs off on the downtime?
The bigger picture
Industrial companies have spent years connecting plant equipment to data platforms for analytics and predictive maintenance. That brings IT-style software, and IT-style bugs, into environments where uptime matters most. A flaw that needs no password and one packet shows why OT networks should not let data services such as databases accept connections from anywhere. Once researchers publish the mechanics of a bug, as Ridge has here, writing an exploit tends to get easier, so the period between public details and patching is when unexposed, updated systems matter most.
What’s next
Watch for any sign of exploitation, for inclusion in government exploited-vulnerability lists, and for advisories from industrial software vendors that embed TDengine and must ship their own updates. Operators that cannot upgrade soon should confirm that port 6030 is reachable only by the hosts that need it.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story






