NEWS

One Packet, No Password: High-Severity TDengine Zero-Day Threatens Industrial Servers

A high-severity zero-day, CVE-2026-42542, crashes TDengine time-series database servers with one packet — 730,000+ instances run in OT, IoT, and energy.

Dylan H.

News Desk

September 29, 2026
6 min read
One Packet, No Password: High-Severity TDengine Zero-Day Threatens Industrial Servers

Unauthenticated Packet Can Crash Widely Deployed Time-Series Database

A high-severity zero-day vulnerability, tracked as CVE-2026-42542, affects TDengine, an open-source time-series database used across industrial, IoT, energy, and automotive environments. Researchers at Ridge Security found that an unauthenticated remote attacker can crash a vulnerable taosd server process by sending a single specially crafted network packet — no credentials, no session, and no user interaction required. TDengine's vendor, TAOS Data, states that more than 730,000 instances of the database are currently running worldwide, with customers reportedly including Siemens, McDonald's, Sinopec, and NavInfo. TAOS Data has released a fixed release, version 3.4.1.6, and Ridge Security reports no evidence of in-the-wild exploitation or public exploit code as of disclosure.


Details

AttributeValue
CVE IDCVE-2026-42542
CVSS Score7.5 (High)
Vulnerability ClassInteger underflow leading to out-of-bounds heap access
Affected ProductTDengine (taosd server)
Affected Versions3.4.0.0 through 3.4.1.5
Patched Version3.4.1.6 and later
Attack VectorSingle unauthenticated RPC packet over TCP/6030
Authentication RequiredNone
Discovered ByRidge Security Threat Research Team
VendorTAOS Data
Disclosure TypeCoordinated disclosure
Exploitation StatusNo known in-the-wild exploitation; no public exploit code
Confirmed ImpactDenial of service (crash); RCE not confirmed

How It Works

The vulnerable code path

According to Ridge Security's technical writeup, the flaw sits in the routine TDengine's taosd server uses to parse incoming RPC messages and retrieve user-identity information — logic that, by design, runs before any authentication check takes place. The calculation subtracts both sizeof(STransMsgHead) and a required user-information offset from the incoming message length (msgLen). If an attacker sends a message shorter than expected, that subtraction wraps around due to unsigned-integer conversion, producing an extremely large value.

From underflow to crash

That wrapped-around value is then passed directly into a memcpy call, triggering an out-of-bounds heap read and causing the taosd process to terminate abnormally. Because the parsing logic executes prior to any identity verification, the attacker needs no valid credentials, no active session, and no prior foothold — only network reachability to TCP port 6030, the port TDengine listens on for client and inter-node RPC traffic.

Why it matters for OT networks

Ridge Security's researchers described the bug bluntly: "CVE-2026-42542 is a three-line fix guarding a subtraction, in a function that runs before anyone has proven who they are, on a port that in too many networks is reachable from too many places... That is not an exotic failure. It is an ordinary one, in an important place." The firm flagged particular risk for organizations where TDengine sits on a flat OT or device network — where "internal" effectively means reachable by a large number of hosts — and where the database was deployed by a systems integrator or bundled inside a vendor appliance, meaning the operating team may not even know it is running. Because repeated transmission of the crafted packet can sustain a restart loop, an attacker with sustained access to port 6030 could hold the database in an ongoing outage rather than a single crash event.

Impact Assessment

Impact AreaDescription
AvailabilitySingle packet crashes taosd; repeated packets can sustain a restart loop and denial of service
Industrial OperationsLoss of time-series telemetry (sensor, PLC, and historian data) during outages
Exposure Blind SpotsTDengine embedded in third-party appliances or integrator-deployed stacks may be unknown to the operating team
Attack ComplexityLow — no authentication, no user interaction, only network reachability to TCP/6030 required
Confirmed SeverityDenial of service only; no confirmed remote code execution or data compromise
Patch FrictionOT environments often defer updates due to maintenance windows and vendor support constraints

Recommendations

For OT and industrial asset owners

  • Inventory every instance of TDengine, including copies bundled inside vendor appliances, integrator-delivered systems, or historian/SCADA add-ons that may not be obvious from an asset list.
  • Upgrade all identified instances to TDengine 3.4.1.6 or later as soon as maintenance windows allow.
  • Where immediate patching is not possible, restrict network reachability to TCP/6030 using firewall rules or network segmentation so the port is not exposed beyond the hosts that genuinely require it.

For security teams

  • Treat any host running taosd on a flat or under-segmented network as a priority for microsegmentation, regardless of whether patching has occurred.
  • Monitor for unexpected taosd process restarts or crash-loop behavior, which could indicate active exploitation attempts even in the absence of a public exploit.
  • Coordinate with vendors and integrators to confirm whether appliances or third-party platforms in the environment embed TDengine, and request patch timelines directly from those vendors.

For administrators managing TDengine directly

  • Apply the vendor patch (3.4.1.6+) and verify the running version post-upgrade rather than assuming an update succeeded.
  • Review firewall and network ACLs to ensure TCP/6030 is not reachable from untrusted segments, remote-access VPNs, or the broader corporate network.
  • Subscribe to TAOS Data's security advisories to stay current on future TDengine vulnerabilities.

Key Takeaways

  1. CVE-2026-42542 is a CVSS 7.5 integer-underflow bug in TDengine's taosd server that lets an unauthenticated attacker crash the process with one crafted packet over TCP/6030.
  2. TAOS Data reports over 730,000 instances of TDengine running globally across industrial, IoT, energy, and automotive deployments.
  3. The flaw is confirmed as a denial-of-service issue — remote code execution and active exploitation have not been confirmed.
  4. Risk is elevated on flat OT networks and in deployments where TDengine is bundled inside third-party appliances, making it invisible to the operating team.
  5. A fix is available in TDengine 3.4.1.6; organizations unable to patch immediately should restrict access to port 6030 as a compensating control.
  6. No public exploit code or in-the-wild exploitation has been reported as of disclosure, but Ridge Security notes that could change given the low attack complexity.

Sources