A newly disclosed flaw in an open source database used in industrial and Internet of Things (IoT) environments could let unauthenticated attackers crash vulnerable servers with a single specially crafted network packet.
TDengine released a fixed version of the software (3.4.1.6) after Ridge Security reported the vulnerability to it.
Ridge Security said attackers who successfully exploit CVE-2026-42542 can trigger a denial-of-service condition on the affected server.
They should also restrict access to TCP port 6030, the database's default RPC port, Ridge recommended.
Ridge Security researcher Yan Zhou says the bug is relatively easy to exploit for an attacker with network access to port 6030.