That's a dependency: if you want your system to be secure, you depend on the software running on your system to be patched when a security flaw is published.
The attack vectors against this firmware are virtually always physical right? As in, hardware access in one way or another (including radio waves reaching the device), not something that can be routed over a (cell) network