I don't know about Tesla specifically, but in general the security of embedded firmware is pretty catastrophic [1]. OTA updates are definitely a two-edged sword: on the one hand, they allow vulnerabilities to be fixed (without taking the car to a service center); on the other, the update process can itself be an attack target (e.g. man in the middle serves firmware image with malware included).
[1] https://www.usenix.org/system/files/conference/usenixsecurit...