If each LTE terminal has a publicly routable IP, unless it's statefully firewalled, any random Internet user who can figure out my IP can run up my data bill, or packet me and inflict a Denial of Service. I remember long ago, some mobile operators in the U.S. were assigning public (non-firewalled) public IPv4 IPs to mobile devices... Attackers were literally scanning Sprint's mobile IP ranges for open port 22 and logging in over SSH as root/aspen to hack jailbroken iPhones!
Taken another way: it's easier to statefully filter incoming flows (FW) than it is to statefully map flows (NAT) both from an implementation and operation perspective.
Only yesterday I had to wheel out Wireshark to prove to a telephony services provider that their bod had forgotten to update a PBX with its changed WAN address.