TDengine Flaw Lets Unauthenticated Attackers Crash Industrial Databases With One Packet
A high-severity vulnerability in the TDengine time-series database can allow an unauthenticated remote attacker to crash a server with a single malformed packet, according to research disclosed by Ridge Security.
The flaw, tracked as CVE-2026-42542, affects TDengine versions 3.4.0.0 through 3.4.1.5 and is fixed in version 3.4.1.6. It stems from an integer underflow in the database's handling of a length field in its custom binary RPC protocol on TCP port 6030.
No credentials, valid session or user interaction are required if an attacker can reach the service. A successful attack causes the taosd process to crash, potentially interrupting the flow of time-series data used for industrial telemetry, energy systems, connected vehicles and large-scale device monitoring.
Ridge said it had not observed exploitation when the research was released. The vulnerability creates a denial-of-service condition rather than installing malware, so defenders should not expect conventional file hashes or command-and-control indicators.
Organizations should upgrade to TDengine 3.4.1.6 and restrict port 6030 to known clients. Teams that cannot patch immediately should watch for repeated taosd segmentation faults, service restart loops, unexplained gaps in telemetry ingestion and short-lived connections to the RPC port from unfamiliar sources.
Asset discovery is especially important because TDengine may be embedded in appliances or vendor-delivered platforms. Operators should ask suppliers whether affected versions are present instead of assuming the database will appear in a standard software inventory.
The risk is operational visibility. Knocking out a telemetry database can obscure conditions in the environment and could be used to distract defenders while another action unfolds. Ridge's disclosure and independent reporting provide additional technical remediation details.


