Firmware updates need to be run with Admin rights from what I know about updating GPU or Motherboard firmware.
AV software have the ability to stop Autorun and scan USB drives once they are plugged in.
While its still possible most firmware infection come preinstalled or by downloading them from unofficial sites or
there is a risk if you buy a second hand Motherboard or Router that the previous owner installed malware hidden inside the firmware on the device.