A newly discovered vulnerability in TDengine, a popular open source time-series database, poses a significant threat to servers used in industrial and Internet of Things environments. This zero-day flaw, identified as CVE-2026-42542, allows attackers to crash vulnerable servers with just one specifically crafted network packet. The database is widely used across various sectors including manufacturing, energy, automotive, and IoT to manage and analyze extensive data from sensors and equipment.
Currently, there are over 730,000 instances of TDengine in operation worldwide, employed by companies such as Siemens, McDonald's, and Sinopec. Ridge Security researchers uncovered this vulnerability during their assessment of open source applications typically overlooked by traditional IT security tools. The flaw is due to an integer-underflow bug in TDengine's message parsing, occurring before user authentication.
The vulnerability affects TDengine versions 3.4.0.0 through 3.4.1.5. A fix has been issued in version 3.4.1.6. Though no known exploits have been reported in the wild, Ridge Security has developed a proof-of-concept exploit but has not released it publicly. The impact of this vulnerability could be severe, leading to a denial-of-service condition which can disrupt vital operations and cause data loss, particularly in environments reliant on real-time data.
Organizations using TDengine should promptly update to the latest version and restrict access to TCP port 6030, which is the database's default RPC port. Such actions are crucial to mitigating potential risks and maintaining operational integrity.

