Normally you can block any device's update if you figure out the server for the update content/update check, and block it out from your router and/or DNS.
The remedy for that is to encrypt the communication
The remedy for that is to MITM the server connection
The remedy for that is HSTS...
It's a cat a mouse game, the better solution for society (imo) is to have specific rights enshrined by law to allow for a qualified 3rd parties to access a system's internals.
Of course, that'll then get attacked via the legal system for violating DRM.. ugh
[0] https://en.wikipedia.org/wiki/Intel_Management_Engine#Undocu...