WatchGuard has identified three vulnerabilities in its wireless access point platform, including two critical flaws that could allow an unauthenticated network attacker to gain API access and execute arbitrary shell commands. The issues affect WatchGuard AP firmware versions 1.0 through 3.4.7 and were fixed in version 3.4.8, which organizations should deploy immediately. The first two issues received critical CVSS v4.0 scores of 9.3, while the third was rated high severity at 8.6.

Critical WatchGuard AP Flaws The combination of unauthenticated access control bypass and command injection poses a serious risk to organizations where AP management services are accessible from untrusted, poorly segmented, or remote-access networks.

In practice, compromising a wireless access point can provide an entry point into a corporate network, potentially allowing an adversary to alter device configurations, disrupt wireless connectivity, intercept traffic relevant to the AP, or use the device as a pivot for internal reconnaissance and lateral movement. This vulnerability is particularly concerning because network appliances are often left exposed and unpatched for extended periods, making them high-priority assets, especially in branch locations and distributed wireless deployments. Organizations should inventory devices running versions prior to 3.4.8, prioritize systems connected to management networks or exposed client segments, and ensure successful firmware deployment.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort.