An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.
WatchGuard is not aware of any exploitation of this vulnerability in the wild.