You'd need to downgrade the firmware in the Spansion flash as well, else it will fail code-signing. You must not change the eMMC version without also changing the Spansion firmware. The Spansion uses CFI if you unsolder it.
I believe that the Fusee Gelee exploit tweaked for Tesla would allow access to everything without unsoldering, but for some reason that is being kept under wraps. No idea why, since the sploit can only be closed by changing hardware.