Only if the device is accessible from the Internet or connects out to the Internet (and to comprised hosts) though. This doesn’t seem a huge risk as those aren’t computers that go to random sites. Most streamers won’t be getting updates after a few years at most anyways.
One could take away their Internet access if one is concerned that, e.g., the original domain falls into bad hands and a new owner installs malware through firmware updates. Or just turn off the update feature. Maybe this would be prudent. They don’t need internet access to work as Roon endpoints.