Back Darkreading One Packet Can Crash OT Servers in Industrial Sectors
A high-severity zero-day vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments.
A newly disclosed flaw in an open source database used in industrial and Internet of Things (IoT) environments could let unauthenticated attackers crash vulnerable servers with a single specially crafted network packet.
The zero-day vulnerability, tracked as CVE-2026-42542 affects TDengine, a time-series database that organizations in sectors like manufacturing, energy, automotive, and IoT use to store and analyze large volumes of data collected over time. Examples of such data include readings from sensors and industrial equipment, as well as application- and infrastructure-related performance metrics.
TDengine says more than 730,000 instances of the database are currently running in organizations ranging from startups to large multinationals across multiple industry sectors. The company's customers include Siemens, McDonald's, Sinopec, and NavInfo.
An Ordinary Failure in an Important Place
Researchers from Ridge Security discovered the vulnerability while testing open source applications used in IoT and operational technology (OT) environments that, according to the company, traditional IT security tools typically tend to overlook.
Related: You Need Cyber Deception for OT
"CVE-2026-42542 is a three-line fix guarding a subtraction, in a function that runs before anyone has proven who they are, on a port that in too many networks is reachable from too many places," the company said in a report disclosing the flaw. "That is not an exotic failure. It is an ordinary one, in an important place."
The high-severity vulnerability (CVSS score: 7.5) affects TDengine versions 3.4.0.0 through 3.4.1.5. TDengine released a fixed version of the software (3.4.1.6) after Ridge Security reported the vulnerability to it. So far, there is no evidence of any attacks targeting the vulnerability in the wild, and no exploit code appears to have become public either, according to Ridge Security, but that could change. The security vendor itself has developed a proof-of-concept exploit for the vulnerability but has chosen not to publicly disclose it.
Ridge Security said attackers who successfully exploit CVE-2026-42542 can trigger a denial-of-service condition on the affected server. The impact could be particularly significant in industrial telemetry , IoT, energy and utilities, connected vehicles , and other operational environments, where losing access to the database can mean losing visibility into equipment and operations, the security vendor said. It recommended that organizations using the database upgrade to the fixed version. They should also restrict access to TCP port 6030, the database's default RPC port, Ridge recommended.
Related: How an Emerging Industrial Protocol Family Could Put OT at Risk
Ridge Security researcher Yan Zhou says the bug is relatively easy to exploit for an attacker with network access to port 6030. "The vulnerability can be triggered with a single malformed network packet, without requiring credentials or an established session," Zhou tells Dark Reading. "Based on the technical details provided in the vendor advisory and the patch changes, reproducing the issue would likely take hours rather than weeks.”
An Integer-Underflow Issue
The flaw is an integer-underflow bug in TDengine's pre-authentication message parsing, meaning the bug is triggered when the server is processing the initial network request from a client before TDengine even verifies who is connecting.
An integer underflow occurs when a calculation produces a number smaller than the system can represent. Instead of producing an error, the value can wrap around to a very large number. For example, if a system tracks items using a counter that cannot store negative numbers, subtracting 1 from 0 can turn the value into the high billions. Attackers can exploit the behavior to bypass security checks, corrupt data, or crash a program.
With CVE-2026-42542, an attacker with access to port 6030 only needs to send a single specially crafted packet to cause vulnerable TDengine instances to crash.
Related: Multistate Water System Attacks Widen, Iran Suspected
“TDengine's RPC service listens on TCP port 6030 by default, making it relatively easy to identify exposed instances through routine network scanning," Zhou says. "An attacker who already has access to an internal network could similarly discover TDengine systems through standard network reconnaissance ."
The bigger challenge for an attacker is determining whether a particular instance has been patched. However, because the exploit requires only a single packet and carries little cost to attempt, an attacker could simply test all identified instances, Zhou adds.
“The confirmed impact is a denial-of-service condition that can remotely crash the database. In environments that depend on the database for operational monitoring, losing access to that data can have consequences beyond a conventional IT outage," he notes. For example, telemetry generated during an outage may not be recorded, creating gaps in historical data. Similarly, operations teams may lose visibility into the systems and processes they rely on to detect problems and dashboards, analytics, anomaly detection, and other applications that depend on the database may lose their data source.
“Organizations should prioritize applying the vendor's security update as soon as practical," Zhou recommends. However, maintenance windows in the environments in which organizations use TDengine can be limited, and the database may be part of a larger appliance or solution.
"As a result, not every organization will be able to patch immediately, and some may not even realize they are running an affected version," Zhou says. “If an immediate upgrade is not possible, organizations should reduce network exposure to the affected service."
Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.
Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders.
Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications.
His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee.
Want more Dark Reading stories in your Google results?
The State of Cloud Security: The Latest Challenges
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Essential News & Insights from Black Hat USA 2025
Effective Alert Triage: Reducing Noise and Finding Real Threats
Effective Alert Triage: Reducing Noise and Finding Real Threats
Cybersecurity Outlook 2027
Cybersecurity Outlook 2027
Threat Exposure Analytics: Measuring and Communicating Security Risk
Threat Exposure Analytics: Measuring and Communicating Security Risk
Benchmark Scores Are a False Flag
Benchmark Scores Are a False Flag
Building an Effective Red Team: Beyond Penetration Testing
Building an Effective Red Team: Beyond Penetration Testing
Vehicle Tire Pressure Sensors Enable Silent Tracking
Trio of Critical Bugs Spotted in Delta Industrial PLCs
AI in OT Sparks Cascade of Complex Challenges
Critical Railway Braking Systems Open to Tampering
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
