This study examines security vulnerabilities in a publicly accessible IoT-based smart waste system using Nmap, Wireshark, and OWASP ZAP to assess network services, packet traffic, and the web application layer. Results were mapped to the OWASP IoT Top 10 (2018). Because the assessment was external black-box testing without exploitation, the mapping is indicative rather than comprehensive. Nmap identified several active TCP ports, although only six open ports were explicitly documented. Wireshark captured 62,591 packets, indicating port-scanning activity and ongoing TCP communication. OWASP ZAP identified 14 web application weaknesses: six medium, five low, and three informational, with no high-risk findings. Four OWASP IoT Top 10 categories (I2, I3, I7, and I9) were supported by direct evidence, while I1 and I5 require further verification and I4, I6, I8, and I10 were outside the testing scope. Key risks involved insecure network services, default settings, and inadequate data protection during transmission and storage.
Copyrights © 2026