This is a problem, and was already fixed by a firmware update.
I think it's also worth mentioning that this vulnerability, although scary, occurs only if the the attacker has
physical access before setup of the seed.
It's nothing you need to really worry about if you buy directly from Ledger.
And if you care at least a minimum about security, you would never buy a Ledger Wallet from third party re-sellers.
TLDR: ledger hardwallet is still pretty safe, much safer than any hot wallet. Unless you have an airgapped PC, hardwallet is still a good choice.