Maybe not best example & I dont know a whole load about the Allwinner SoCs (except they are a bit cheap and theyve previously left a massive backdoor open) or other components in the Pinephone.
Looks like anyone can flash unsigned firmware? Which, given theres been cases of phones having malware added in the supply chain, isnt great.
The age of the SoC & fact that Allwinner etc. have long given up support makes it feel likely there will be other vulns. Maybe the Pinephone and Sunxi...