I'd agree it certainly isn't as big as they seem to convey. That being said, demonstrating that the blast radius of a compromise might be larger or harder to detect than thought is at least something. You wouldn't immediately assume that compromising an admin would allow a users password to be compromised via the 2fa system.
Definitely more "reason 24332456664 passwords aren't the best" than "groundbreaking vulnerability".