Critical Pre-Authentication Vulnerability in TDengine Exposes Industrial and IoT Systems to DoS Attacks
Security researchers at Ridge Security have disclosed CVE-2026-42542, a high-severity (CVSS 7.5) pre-authentication vulnerability in TDengine, an open-source distributed time-series database widely used in industrial telemetry, energy, utilities, connected vehicles, and IoT environments. The flaw allows an unauthenticated remote attacker to crash the database server with a single malformed network packet, requiring no credentials, valid session, or user interaction.
Key Details
- Affected Versions: TDengine 3.4.0.0 through 3.4.1.5
- Fixed Version: 3.4.1.6
- Vulnerability Type: Integer underflow in TDengine’s custom binary RPC protocol (TCP port 6030), leading to a heap buffer overflow and segmentation fault when processing a crafted packet.
- Impact: Denial of service (DoS), with repeated attacks potentially forcing a crash-and-restart cycle, resulting in lost in-flight writes and disrupted monitoring for operational technology (OT) and telemetry systems.
- Exploitation: The attack requires network access to port 6030, which is often exposed in flat OT or device networks where TDengine may be embedded in vendor appliances or integrator deployments sometimes unbeknownst to operators.
Technical Root Cause
The vulnerability stems from improper handling of the msgLen field in TDengine’s RPC message header. During early connection handling, the server subtracts the fixed header size from the attacker-controlled msgLen value, leading to an integer underflow that triggers a heap overflow when passed to memcpy(). This reliably crashes the taosd process, and if the service is configured to auto-restart, an attacker can sustain the outage by repeatedly sending the malicious packet.
Detection and Mitigation
- Primary Fix: Upgrade to TDengine 3.4.1.6 or later.
- Workarounds:
- Restrict network access to port 6030 via firewall rules or ACLs, limiting exposure to only trusted application hosts.
- Inventory environments for embedded TDengine instances, as OEM or bundled deployments are most likely to be overlooked.
- Detection Indicators:
- Repeated
taosdsegmentation faults in logs (dmesg, kernel journal, or core dumps). - Unexpected short-lived connections to port 6030 from unknown sources.
- Gaps in time-series data ingestion, signaling a downed metrics database.
- Repeated
Broader Context
Ridge Security noted that while the immediate impact is DoS, the underlying memory corruption primitive could theoretically be exploited for remote code execution (RCE) in future attacks. Additionally, the team highlighted two cryptographic weaknesses in TDengine MD5 password hashing and SHA-1 RPC signatures though these are not part of CVE-2026-42542.
In related research, Ridge Security also identified CVE-2026-44639 (CVSS 3.7) in NanoMQ, a lightweight MQTT broker, where an unauthenticated attacker can trigger CPU exhaustion via malformed MQTT v5 packets. Both vulnerabilities underscore the risks in parsing layers of network services, particularly in infrastructure handling machine data.
As of disclosure, no in-the-wild exploitation has been observed, and no public exploit code exists. However, defenders are advised to treat repeated taosd crashes as a security event rather than a stability issue.
TDengine cybersecurity rating report: https://www.rankiteo.com/company/tdengine
"id": "TDE1790339395",
"linkid": "tdengine",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Industrial telemetry, energy, utilities, '
'connected vehicles, IoT',
'name': 'TDengine',
'type': 'Software'}],
'attack_vector': 'Network',
'data_breach': {'type_of_data_compromised': 'Time-series data (in-flight '
'writes)'},
'description': 'Security researchers at Ridge Security disclosed '
'CVE-2026-42542, a high-severity (CVSS 7.5) pre-authentication '
'vulnerability in TDengine, an open-source distributed '
'time-series database. The flaw allows an unauthenticated '
'remote attacker to crash the database server with a single '
'malformed network packet, leading to denial of service (DoS) '
'and potential disruption of operational technology (OT) and '
'telemetry systems.',
'impact': {'data_compromised': 'Lost in-flight writes',
'downtime': 'Crash-and-restart cycle possible with repeated '
'attacks',
'operational_impact': 'Disrupted monitoring for OT and telemetry '
'systems',
'systems_affected': 'TDengine database server (taosd process)'},
'investigation_status': 'Disclosed, no in-the-wild exploitation observed',
'lessons_learned': 'The vulnerability underscores risks in parsing layers of '
'network services, particularly in infrastructure handling '
'machine data. Defenders should treat repeated taosd '
'crashes as a security event rather than a stability '
'issue.',
'post_incident_analysis': {'corrective_actions': 'Fixed in TDengine 3.4.1.6; '
'workarounds include '
'restricting network access '
'to port 6030',
'root_causes': 'Improper handling of the msgLen '
'field in TDengine’s RPC message '
'header, leading to integer '
'underflow and heap overflow'},
'recommendations': ['Upgrade to TDengine 3.4.1.6 or later',
'Restrict network access to port 6030 via firewall rules '
'or ACLs',
'Inventory environments for embedded TDengine instances',
'Monitor for repeated taosd segmentation faults and '
'unexpected connections to port 6030'],
'references': [{'source': 'Ridge Security'}],
'response': {'containment_measures': 'Restrict network access to port 6030 '
'via firewall rules or ACLs',
'enhanced_monitoring': 'Monitor for repeated taosd segmentation '
'faults and unexpected connections to '
'port 6030',
'remediation_measures': 'Upgrade to TDengine 3.4.1.6 or later'},
'title': 'Critical Pre-Authentication Vulnerability in TDengine Exposes '
'Industrial and IoT Systems to DoS Attacks',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'CVE-2026-42542 (Integer underflow leading to heap '
'buffer overflow)'}