Doesn’t it do that with the firmware itself, i.e. verify that the firmware was signed by the manufacturer before updating?
So the HTTP request leaks information about the update and could be MITM, but the result could at best be an older version? (Which could be a known exploitable one!)