TDengine Patches Zero-Day Letting One Packet Crash OT Servers
Ridge Security disclosed CVE-2026-42542, a high-severity flaw in the open-source TDengine time-series database used across manufacturing, energy, automotive and IoT sectors. The bug lets an unauthenticated attacker crash a vulnerable server with a single crafted network packet; TDengine has released version 3.4.1.6 to fix versions 3.4.0.0 through 3.4.1.5.
GoKawiil's interpretation of the reporting above, not reported fact.
TDengine says over 730,000 instances run worldwide at firms including Siemens, McDonald's, Sinopec and NavInfo, so a trivial crash bug in unauthenticated, pre-verification code could disrupt industrial monitoring at scale if exploited. Ridge Security notes no known in-the-wild attacks or public exploit yet, but the firm's own proof-of-concept suggests exploitation is technically straightforward, raising urgency for patching in OT networks where such ports are often reachable more broadly than intended.
- CVE-2026-42542 lets attackers crash TDengine servers pre-authentication with one packet.
- TDengine version 3.4.1.6 fixes the flaw affecting 3.4.0.0 through 3.4.1.5.
- Over 730,000 deployments exist across industrial and IoT sectors, per TDengine.
Source: darkreading.com — Jai Vijayan, 2026-09-28
Published there as: “One Packet Can Crash OT Servers in Industrial Sectors”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.