Impact
TDengine 3.4.1.6 and earlier contain an off‑by‑one buffer overflow in the trimString function used while processing SQL escape sequences such as \%, \_, or \x. The vulnerability writes one byte beyond a stack buffer, which can corrupt execution context, causing a denial of service and, depending on context, remote code execution. The weakness is categorized as CWE-121 and CWE-787.
Affected Systems
The affected product is TAOSDATA TDengine, version 3.4.1.6 and earlier. The issue was addressed in version 3.4.1.14; any installation on those or older versions is vulnerable.
Risk and Exploitability
The CVSS score of 8.3 classifies this as a high‑severity flaw. The EPSS score of less than 1% indicates that active exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. However, based on the CVE description, it is inferred that the flaw can be triggered via malicious SQL input, which suggests it is likely exploitable remotely by an authenticated or unauthenticated user who can send crafted queries to the database. While exploitation probability is low today, the potential to execute arbitrary code warrants prompt remediation.
OpenCVE Enrichment