An authentication bypass on the appliance that decides who is inside. The intruder inherits every assumption built on it.
A session token read out of appliance memory bypasses the second factor entirely, because authentication already happened.
The first flaw supplies the authentication the second one requires. A pair of medium problems is not a medium problem.
A stolen session token arrives after authentication. Multi-factor is not bypassed — it is never consulted.
A control the server can be persuaded to skip is not a second factor. It is a convention.