The risks are more likely to occur when you use a computer infected with malware, e.g., mismatched wallet addresses or anything you copy and paste into the installed software wallet, whether from a hardware wallet or another software wallet. Therefore, double-check the address and others in the hardware wallet for every transaction.
The risk of a hardware wallet firmware being inserted by a trojan tends to be when you buy a fake hardware wallet from an unofficial seller.
You can read several ways to check the authenticity of a hardware wallet on the official website, for example:
- https://coldcard.com/docs/paranoid
- https://support.ledger.com/hc/en-us/articles/4404389367057-Is-my-Ledger-device-genuine-?docs=true
- https://blog.trezor.io/psa-non-genuine-trezor-devices-979b64e359a7
Here is an article that might be useful to add to your insight:
https://www.kaspersky.com/blog/five-threats-hardware-crypto-wallets/47971/