news.mlab.sh
Back to the feed
vulnerability

One Packet Can Crash OT Servers in Industrial Sectors

HighCVSS 7.5
Image: Dark Reading
Summary

A high-severity vulnerability (CVE-2026-42542) in TDengine, a time-series database, allows unauthenticated attackers to crash vulnerable servers with a single crafted network packet. The vulnerability stems from an integer-underflow bug in pre-authentication message parsing. While no attacks have been reported, the ease of exploitation and potential for denial-of-service in critical industrial environments necessitate immediate patching and network restrictions. TDengine released a patch on June 4, 2026, and a fix has been available since April.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.