For some background why IoT products will stop being insecure: if you sell one in the EU, you're liable for all the damage your botnet causes.
Luckily, common EU home routers have firewalls, even for IPv6. And it's so much easier to punch holes on purpose! Instead of messing with port forwarding and internal and external IP addresses, you can just say "this device is a server, please allow traffic on port 80 and 443, thank you"