Skip to finding
important · Firmware

Network access to a WatchGuard AP internal API is sufficient for unauthenticated shell-command execution.

Affects

WatchGuard AP wireless access points running WatchGuard AP software.

The management API contains command injection, while a separate access-control flaw can issue a valid API session without credentials.

Detail and 2 sources

The practical boundary is API reachability: the caller must be able to connect to the access point's internal service.

WatchGuard has published corrected firmware.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 29, 2026