And my understanding is that everything after the 5C is less vulnerable to even this attack (Which itself may not be possible, even with a firmware update.)
Arguably, the fact that the 5C accepts a firmware update without the passcode is a security vulnerability and ought to be patched.