How common are RADIUS deployments that aren't EAP/PEAP based though?
IDK About anyone else but for a very long time anything md5 has been in the same mental bucket as zip or office documents passwords.. a discouragement for the casual user and accidental exposure but not actually secure against any kind of determined attack. ( the accuracy of my mental buckets is perhaps a separate issue )
Although I suppose lots of deployments still go with whatever lowest friction, so maybe lots?