They notably aren't saying that the firmware or loader is doing no validation on the executable. Most likely this has some sort of home grown signature on the blob, because if it didn't they instantly would have cooked up a MitM exploit to demonstrate. The fact that they didn't implies that it doesn't work.
That's not to say this is a good design (it's clearly not) or that it can't be abused in non-malware ways (junkware, etc...). But it does seem like it's being spun as a clear security hole when my guess is that it isn't (it certainly hasn't been shown to be).