A newly disclosed high-severity vulnerability in TDengine, an open-source time-series database used in industrial, IoT, energy and automotive environments, could allow an unauthenticated attacker to crash a server with a single specially crafted network packet. Tracked as CVE-2026-42542 and rated 7.5 on the CVSS scale, the flaw affects TDengine versions 3.4.0.0 through 3.4.1.5. TDengine says more than 730,000 instances are running across organisations including Siemens, McDonald’s, Sinopec and NavInfo.
Ridge Security researchers found the issue while testing software used in operational technology environments. It is an integer-underflow bug in TDengine’s pre-authentication message parsing, before the service verifies a connecting user’s identity. An attacker needs network access to TCP port 6030, the database’s default RPC port, but does not need credentials or an established session.
The confirmed effect is denial of service: crashing the database could interrupt access to industrial telemetry, dashboards, analytics and anomaly-detection systems, and may create gaps in recorded data. Ridge Security said it has developed a proof of concept but has not released it; there is currently no evidence of exploitation in the wild.
TDengine released version 3.4.1.6 to address the vulnerability. Organisations should upgrade as soon as practical and restrict access to TCP port 6030. Where immediate patching is not possible because of maintenance constraints or embedded appliances, Ridge recommends reducing the service’s network exposure.