Firmware updates can't add network hardware where none currently exists. The block diagrams for Pluton don't give it any mechanism to communicate with the network directly.
Anything evil will likely be brokered through the OS. While this is good in that it's not a persistent backdoor like Intel ME, there's still Microsoft skulduggery to worry about.