That subnet is indeed part of the normal RAP software operation. You can see it under the ap-system proflie.
Under normal circumstances, it uses it on the wired port (E1 inside perhaps, depending on type) for provisioning. It also uses it when the RAP is isolated in terms of uplink.
I just checked on my lab controller (same ver as you), and I see the same thing from the RAP.
My theory would be that for some reason, the RAP is sending packets up the tunnel with that source as well as all the other normal stuff (ipsec etc).
Unless it's causing you an operational problem, I wouldn't worry about it.