A password is something you know. A second factor asks for a different kind of proof, such as control of a registered authenticator. A stolen password alone may then be insufficient to sign in.
Different factors reduce some shared failure paths; they do not make every path independent. One deceptive page can capture a password and a typed code. A compromised device may expose several factors or an existing session. The useful question is which attack the extra check stops.