TDengine zero-day crashes OT servers

29 Sep
2026
Ben Liddle
Founder, Nanorisk
1 min
Read
TDengine zero-day crashes OT servers

A zero-day vulnerability has been disclosed in TDengine, a time-series database with significant deployment across industrial, IoT, energy, and automotive environments. The mechanics are blunt: a single malformed packet sent to an exposed TDengine instance is enough to crash the server, and no authentication is required to do it.

High-severity findings in IT systems are serious. In operational technology environments, they carry a different weight. Availability is not just a service metric in industrial settings - it can have direct physical and safety implications depending on what that database is feeding.

If TDengine appears in your own infrastructure, or within a vendor or supplier's environment that connects to yours, this needs to be assessed and not just logged as a patch to schedule. Unauthenticated denial-of-service against OT-adjacent systems is exactly the kind of finding that sits at the top of a penetration test report.

← All insights

Get in Touch

If you would like to discuss an assessment or understand how Nanorisk can support your organisation, please get in touch.