Any thread model should take firmware into account. There have been examples of unauthenticated remote code execution against Intel ME[0]. This isn't theoretical, this isn't an assumption, this has happened. Those exploits are independent of the OS running, with certain configurations the system doesn't even need to be switched on, just plugged in. With fTPM as an ME module (not all fTPMs are such) this provides an additional huge attack surface.