WatchGuard AP 3.4.8 Fixes a Shell Command Flaw That Needs No Login
WatchGuard has fixed three flaws in its access point firmware, including an internal management API issue that could let someone with network access to an AP run shell commands without an AP login. The vendor’s advisories cover WatchGuard AP versions 1.0 up to, but not including, 3.4.8. The repair is 3.4.8.
The advisories were published on 28 September 2026. WatchGuard’s firmware notes date its cloud-managed 3.4.8 build to 24 September. WatchGuard says it is unaware of exploitation of these flaws in the wild.
Three flaws, two different starting positions
| Identifier | What WatchGuard describes | Required starting position |
|---|---|---|
| CVE-2026-101891 | Improper access control in an internal API can yield a valid API session. | No authentication, but network access to the AP. |
| CVE-2026-86102 | Command injection in the internal management API can run arbitrary shell commands on the AP operating system. | Network access to the AP; the vendor’s score assigns no privileges or user interaction. |
| CVE-2026-87969 | Crafted input to the diagnostic CLI can run operating-system commands. | An authenticated administrator. |
WatchGuard rates the two API flaws critical at 9.3 and the diagnostic CLI flaw high at 8.6, using CVSS 4.0. The access-control advisory and command-injection advisory describe separate defects. They do not say that the first must be used to exploit the second. The CLI advisory has a different prerequisite: an administrator session. Treating all three as an unauthenticated exploit chain would overstate what the vendor disclosed.
Network access is also a real boundary. The advisories do not show that every AP exposes its internal API to the public internet or that every wireless client can reach it. An organisation needs to check its own wired, wireless and management paths. A high severity score describes potential impact under the specified conditions; it does not measure how many APs are reachable from an untrusted segment.
A released build is not proof the fleet has it
For WatchGuard Cloud-managed access points, the 3.4.8 release notes identify build v3.4.8-1.B747709 and describe tighter CLI and API service access. The advisories express the affected and fixed range as the firmware version, so operators should compare the installed version on each AP with 3.4.8 rather than infer protection from a release announcement.
That distinction matters when automatic updates are enabled. WatchGuard’s upgrade guide says an account can use a grace period before automatic upgrades, with seven days as the default, and can stagger updates within a maintenance window. An AP that was offline may also miss the first window. Those are deployment settings, not a claim that a particular customer’s devices remain vulnerable. Check the actual device status and pending schedule.
The same guide says an AP reboots after its firmware upgrade and connected wireless clients are temporarily disconnected. A controlled rollout should therefore start with representative locations and confirm that each AP reconnects to management, broadcasts the expected SSIDs, and carries its normal client authentication and VLAN traffic before the next group is updated. This test plan is BlackTree’s operational analysis, not an additional WatchGuard patch requirement.
Reduce reachability while the upgrade is under way
The primary repair is the vendor’s fixed firmware. In the meantime, map which networks can reach an AP’s management address and limit access from guest, user and other untrusted segments where the design permits. Review administrator access to the diagnostic CLI separately. Segmentation and account hygiene can reduce opportunity, but the advisories do not list them as a substitute fix or provide a universal workaround.
For a cloud-managed AP that cannot retrieve its update from WatchGuard Cloud, the vendor’s local Web UI guide describes a manual firmware path. It says to confirm the file matches the AP model and the checksum on WatchGuard’s download page. Use that documented route only after checking the device and release identity; a firmware file for a different AP family is not a safe shortcut.
WatchGuard says it knows of no exploitation. That statement is useful, but it is not evidence that no attempt occurred. The advisories provide no campaign, indicator set or affected-estate count. If an organisation has independent signs of AP compromise, preserve device and network evidence under its incident process rather than treating this disclosure alone as proof of intrusion.
This AP update is distinct from BlackTree’s earlier Firebox VPN-flaw report. Fireware OS and WatchGuard AP have different firmware lines and patch decisions. For the AP estate, the concrete next step is to verify installed 3.4.8, check management-network reachability and complete a staged wireless-service test.
Sources
- WatchGuard AP access-control advisory, published 28 September 2026.
- WatchGuard AP internal-API command-injection advisory, published 28 September 2026.
- WatchGuard AP diagnostic-CLI advisory, published 28 September 2026.
- WatchGuard Cloud-managed AP firmware release notes, 3.4.8 build dated 24 September 2026.
- WatchGuard access point firmware upgrade guide and local Web UI guide, checked 30 September 2026.


