Check out the slides in the "Various" section: https://tomverbeure.github.io/2019/03/13/SweRV.html#various
It shows how 2 SweRVs are used inside a NAND flash controller.
So a remote attacker who already had root access to run fwtool could do it.
...yeah, a lot...? Over SATA link? I don't know, over NVMe? maybe, over regular PCIe? a lot, over USB? a lot...
Adversaries won't have to physically plug the device in, though, because there are plenty such potentially exploitable devices that are readily available on average computers(desktop or laptop). BIOS ROM chips, gaming RGB LED controllers, motion sensors, power management microcontrollers, internal Wi-Fi or Bluetooth chips, potentially some HDMI monitors, SSDs, HDDs, potentially Blu-ray drives, certain USB drives, gaming mice, GPUs, high end network controllers, BMCs for remote server management... Today even a microSD card runs some sort of software.
I think you'd have to go back to at least Pentium 2 or III days, further back if you want a laptop, to be confident that there is _no_ standalone microcontrollers that can be hacked from OS by adversaries, and that any reprogramming features in components are/can be fully disabled in hardware or at least by OS. Microcontrollers were usually overkill for simple management tasks back in those days, and ROMs either had hardware write enable pins or external reprogramming voltage supply required to do it.
Yes, most devices (including hard drives) can have their firmware updated from the host computer. Some newer devices support some form of firmware signing, making it more difficult for a malicious firmware to be installed, but they're in the minority -- most firmware update mechanisms are insecure.