The IPv6-in-IPv4 protocol (RFC4213) does not require authentication of incoming packets allowing an attacker to spoof and route traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.