I explored this issue many years ago and, at least at the time, it was my understanding that for many motherboards it's simply not possible to introduce unsigned code through software alone.
you could always check if there is a signature with binwalk or smtg if it makes you feel safer
Certificate in DER format (x509 v3)
SHA256 hash constants, little endian
Very interesting to dig around in the firmware, I even found the boot splash image. Definitely a time sink, but fun.