We shipped the first software with an old dropbear, though it had backported patches for the known CVEs: http://cgit.openembedded.org/openembedded-core/tree/meta/rec...