important · Firmware
Network access to a WatchGuard AP internal API is sufficient for unauthenticated shell-command execution.
Affects
WatchGuard AP wireless access points running WatchGuard AP software.
The management API contains command injection, while a separate access-control flaw can issue a valid API session without credentials.
Detail and 2 sources
The practical boundary is API reachability: the caller must be able to connect to the access point's internal service.
WatchGuard has published corrected firmware.