In the current firmware release (1.6.1) the ACLs only support IP addresses, however starting firmware version 2.0 (releasing later this month) ACL support has been extended to also allow subnets (IP address and mask)
So in release 2.0 you will be able to setup ACL rules in the guest WLAN to block access to the subnet used for management or any other internal subnet and only allow access to the default gateway so clients can access the internet.