VYPR
Unrated severityNVD Advisory· Published Oct 28, 2022· Updated May 6, 2025

Lock WARP switch bypass using warp-cli 'add-trusted-ssid' command

CVE-2022-3512

Description

Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced on an affected endpoint.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Using warp-cli 'add-trusted-ssid', a local user can disconnect WARP and bypass the Lock WARP switch, circumventing Zero Trust policies.

Vulnerability

The vulnerability resides in the Cloudflare WARP client's warp-cli tool. The add-trusted-ssid command, intended for managing trusted SSIDs, can be abused to disconnect the WARP client and bypass the "Lock WARP switch" feature. This allows a user to disable the WARP client, preventing enforcement of Zero Trust policies. Affected versions include Cloudflare WARP client versions prior to the fix released in October 2022 [1].

Exploitation

An attacker with local access to the endpoint can execute the warp-cli add-trusted-ssid command. No authentication beyond local user privileges is required. The attacker can disconnect the WARP client, effectively disabling the VPN and bypassing the Lock WARP switch. The attack does not require user interaction or network access [1].

Impact

Successful exploitation allows the attacker to bypass Zero Trust policies enforced by Cloudflare Secure Web Gateway. This results in loss of confidentiality and integrity as network traffic is no longer inspected or filtered. The attacker can access resources without policy enforcement, potentially exposing sensitive data or allowing malicious activity [1].

Mitigation

Cloudflare released a fix in October 2022. Users should update the WARP client to the latest version. There is no known workaround; updating is the recommended mitigation. The vulnerability is not listed on CISA's KEV [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.