@TheLakeHouseIT, Since the AP HTTPs is enabled and the services are turned off. It's not vulnerable.But, I would recommend to turn off the HTTPs service on the AP's using "set http/https disable"Have you tried accessing the AP GUI through browser
@Jakezxz1 By default all the AP's connecting to vSZ will get HTTP/HTTPS disabledYou can confirm the same by logging to AP CLI (SSH) and execute the below commands,"get http" and "get https", this will provide you the status of GUIAlso, you ca try pic...