Reminds me of that classic OSX root login bypass by not using a password from 3 years ago: https://ma.ttias.be/root-login-without-password-allowed-defa...
If you want to prevent this you need full disk encryption
To protect from that threat you need secure boot which verifies checksums from BIOS to kernel.
Secure boot, and temper-evident device seals, form the outline of a solution. As far as I know though, these are still far from foolproof. Really I would say defending from an evil maid attack is still an open problem.
Something very similar holds for theft of devices that are still on.