What prevents downgrading? Is simply a software issue or is there some hardware mechanism in place?
Technically you can downgrade to exploitable firmware but only if the system had exploitable firmware in the first place, and had its firmware backed up, before being updated.