Still on Drupal 7? Security support for Drupal 7 ended on 5 January 2025. Please visit our Drupal 7 End of Life resources page to review all of your options.
Note that while related with the TFA link vulnerability in version 8.x-1.0-alpha8 of this module, the bug here is a lot milder, as only the user that inserted the username and password can access the TFA entry form. Even though that form doesn't expire, the flood control mechanism strongly limits the number of possible attempted guesses before the window for that guess expires and invalidates the attack.