I'm not that knowledgeable in therms of boot loading, but I'm kinda sure you need to find something like what I quoted above and find a way to overload it with a bunch of useless code causing it to load into a vulnerable state like frogminer for instance, then load your unauthorized applications.
Edit: Didn't mention the Sudoku exploit which deals with save editing overloading