There is no published attack for the full-round AES.
Also with CBC the first block still looks the same, and since there is likely to be the jump table there, you have a bit of plausible known plaintext to work on.
One could add some "salt" into it to make it harder but I really think that in the context of boot loaders, firmware OTA, etc, and that EU regulation (actual or the intent) this is way off reality.
It will be easier to break the RDP security. I reckon it is breakable on nearly all MCUs already, and anyway there are firms which will decapsulate the package and read out the FLASH directly. But again the EU reg cannot be aimed at this because every "industrial grade" chip is vulnerable. Only specialised smartcard type chips have any hope.