The issue here is not motherboard can execute arbitrary code. Motherboards are trusted hardware. You pass all your keystrokes, network traffic and memory transfers over it.
The issue is motherboard uses its trusted status to run software that performs raw HTTP downloads for firmware. Which is probably bad but might alternatively just be futureproofing to avoid having to deal with expiring certs.