There are two ways around that.
First, if you happen to be attacking your neighbor and you share L2 WAN with them, you simply put the 10.x address in as destination IP and the neighbor MAC address as destination MAC. Done. No NAT required, the traffic will just pass.
Second, some NAT implementations look at only a three-tuple of IP, port, and protocol. If you connect from port 40000 to some random site, the NAT will translate that to a different port, say 30000, and it will allow any traffic from the entire world to port 30000 to hit port 40000 on your device. Hopefully your device does not have anything running on 40000 so it will all be fine -- but it might not be. This type of NAT used to be VERY popular, because it makes things like P2P traffic work without having to configure anything.