The firmware updates could come over a TV broadcast at some point.
Some years ago there was a paper about transmitting malicious TV signals and getting code exploitation on TVs, so that is another thing to worry about.
There's been talk in the past about delivering data to STBs via closed-captioning side channels [1]. I don't know if it ever was actually done, but I've got to imagine there's even more room in modern broadcasts for this sort of thing.
Funny how Vizio already got fined for almost exactly this. But now it's back as a ""feature"" for advertising.