Single Malicious Packet Can Crash Industrial Databases, Researchers Warn
Security researchers have disclosed a high-severity zero-day vulnerability in TDengine, a time-series database used widely across industrial, IoT, energy and automotive environments. The flaw reportedly allows an attacker to crash affected servers by sending just one malicious network packet, making it a low-effort but potentially high-impact attack.
Because TDengine is embedded in operational technology (OT) systems that monitor and control physical processes, a successful attack could disrupt critical services, from energy monitoring to industrial equipment management. Denial-of-service attacks against OT infrastructure are particularly concerning because downtime can have real-world safety and operational consequences beyond typical IT outages.
Organisations using TDengine, or products built on it, should check with vendors for patch availability and monitor official advisories closely as more details emerge.