Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/SNAP headers, and converting frames from Ethernet to Wifi and its reverse.
https://www.kb.cert.org/vuls/id/855201
https://standards.ieee.org/ieee/802.2/1048/
https://standards.ieee.org/ieee/802.1Q/10323/
https://kb.cert.org/vuls/id/855201
https://datatracker.ietf.org/doc/draft-ietf-v6ops-ra-guard/08/