The trezor vulnerability being disclosed by Kraken today was already a known attack vector. All trezor models are vulnerable to physical attack unless you use a strong passphrase. The attacker can easily pull the seed from the device but they would then have to brute force your passphrase to steal the funds. Longer passphrases are better. The fact that you can't enter the passphrase directly on the device in the older trezors isn't ideal because an attacker could compromise your computer to obtain the passphrase - no brute force necessary.
https://twitter.com/krakenfx/status/1223253508956266496
https://twitter.com/krakenfx/status/1223253508956266496