Update: I ended up just using the device when i link it to trezor suite it didnt detect any installed Firmware
so i just installed the firmware then generated a seed and did a factory reset then regenrate a new seed and used
a passphrase Now i just deposited 120$ and im planning to wait 1-3 months to see if everything is good or the wallet
will get drained

If the hardware device was compromised, updating the firmware to the latest version should overwrite any malicious file. So, you should be fine. Having said that, I just want to add that If you've funds untouched in a compromised wallet doesn't make it any safe. Though, it depends on the malware deployed. Dark skippy for example requires the owner to sign two transactions before an attacker can remotely steal the seed phrase. The first transaction reveals the first half of the seed and the second transaction reveals the second half.