Hopefully it is some arcane MSCHAP bug that the introduced in that firmware and will fix with the next one and you can be back to a minimal level of encryption in your radius auth. It is pretty lame ...
There's potentially an easy mitigation here, since the access accept response can also provide additional parameters to the RADIUS client, which could be in the form of a VLAN ID, IP Address, Access ...